CVE-2006-6528: High severity Drupal Chatroom Module vulnerability
Published Dec 14, 2006
·Updated
The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.
Affected Software
1 affected component
Drupal Chatroom Module<=4.7
Event History
Dec 14, 2006
CVE Published
01:28 AM
Data Sourced
via NVD·01:28 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6528?
CVE-2006-6528 has a high severity rating due to its potential for session hijacking.
2
How do I fix CVE-2006-6528?
To fix CVE-2006-6528, upgrade the Chatroom Module to version 4.7.x-1.0 or later.
3
What are the potential impacts of CVE-2006-6528?
The potential impacts of CVE-2006-6528 include unauthorized access and privilege escalation for attackers.
4
Who is affected by CVE-2006-6528?
Users of the Chatroom Module for Drupal prior to version 4.7.x-1.0 are affected by CVE-2006-6528.
5
Can CVE-2006-6528 be exploited remotely?
Yes, CVE-2006-6528 can be exploited remotely by attackers to hijack sessions.