Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 安全漏洞
Vulnerability Description
Drupal是Drupal社区的一套使用PHP语言开发的开源内容管理系统。 Drupal 5.10 版本和 6.4版本存在安全漏洞。该漏洞源于有可能不会对一个https会话里的会话cookie设置安全标记, 这会引起在http请求中发送cookie并使远程攻击者捕获该cookie变得简单。
CVSS Information
N/A
Vulnerability Type
N/A