Drupal Session Fixation Vulnerability - CVE-2008-3222
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3 when contributed modules quotterminate the current request during a login eventquot allows remote attackers to hijack web sessions via unknown vectors.