Lucene search

K
cve[email protected]CVE-2007-0506
HistoryJan 26, 2007 - 12:28 a.m.

CVE-2007-0506

2007-01-2600:28:00
web.nvd.nist.gov
17
cve-2007-0506
drupal
project issue tracking
access control
file access

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.7%

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.

Affected configurations

NVD
Node
drupalprojectMatch4.6
OR
drupalprojectMatch4.6_1.1
OR
drupalprojectMatch4.7
OR
drupalprojectMatch4.7_1.1
OR
drupalprojectMatch4.7_2.1
OR
drupalprojectMatch5.0dev
OR
drupalproject_issue_tracking_moduleMatch4.7
OR
drupalproject_issue_tracking_moduleMatch4.7_1.1
OR
drupalproject_issue_tracking_moduleMatch4.7_2.1
OR
drupalproject_issue_tracking_moduleMatch5.0dev

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.7%

Related for CVE-2007-0506