6.8

CVE-2013-7302

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ubercart ≫ Ubercart Version 6.x-2.0
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta5
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta6
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update dev
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc5
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc6
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc7
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.6
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.7
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.8
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.9
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.10
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.11
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.12
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update dev
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.5
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.68
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://drupal.org/node/2158565
Patch
https://drupal.org/node/2158567
Patch
https://drupal.org/node/2158651
Patch
Vendor Advisory