VendorsTim Nelsonshared_sign-onall versions
Vulnerabilities

Tim Nelson Shared Sign-on

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-3656
Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
Published 2009-10-09 · Modified
6.8EPSS 0.006
CVE-2009-3657
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
Published 2009-10-09 · Modified
5.8EPSS 0.011