Description
Drupal Core is prone to a session hijacking vulnerability. Exploiting this issue may allow attackers to access another user's session, thus giving them the opportunity to do anything the affected user is authorized to do. Drupal Core versions 6.x ranging from 6.0 and up to and including 6.33 are vulnerable.
Remediation
Update to Drupal Core version 6.34 or latest
References
Related Vulnerabilities
WordPress Plugin LearnPress-WordPress LMS Cross-Site Scripting (4.1.6.5)
WordPress Plugin WordPress for Google Maps-WP MAPS Cross-Site Request Forgery (4.2.3)
WordPress Plugin Power Charts-Responsive Beautiful Charts & Graphs Cross-Site Scripting (0.1.0)
WordPress Plugin WordPress Backup to Dropbox Cross-Site Scripting (4.0)