CVE-2009-4533

Metadata

CVE-2009-4533
5.0
drupal.org, drupal.org, drupal.org, securityfocus.com, vupen.com, exchange.xforce.ibmcloud.com
2009-12-31
2017-08-17 06:10

Description

The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholders for a default value, which allows remote attackers to read session variables via unspecified vectors.

Related Vulnerabilities