Lucene search

K
cveMitreCVE-2008-2271
HistoryMay 16, 2008 - 12:54 p.m.

CVE-2008-2271

2008-05-1612:54:00
CWE-269
mitre
web.nvd.nist.gov
29
site documentation
drupal
module
cve-2008-2271
vulnerability
database
access control

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

73.8%

The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the “access content” permission to list tables and obtain session IDs from the database.

Affected configurations

Nvd
Node
site_documentation_projectsite_documentationRange5.x-1.05.x-1.8drupal
OR
site_documentation_projectsite_documentationRange6.x-1.06.x-1.1drupal
VendorProductVersionCPE
site_documentation_projectsite_documentation*cpe:2.3:a:site_documentation_project:site_documentation:*:*:*:*:*:drupal:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

73.8%

Related for CVE-2008-2271