CVE-2014-9015

medium
Published 2014-11-24 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/SA-CORE-2014-006

OS impact

OSVersionStatusFixed in
debian debian7.0affected

Application impact

VendorProductVersionsFixed
drupaldrupal{"startIncluding":"6.0","endExcluding":"6.34"}6.34

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.