Lucene search

K
cve[email protected]CVE-2008-3745
HistoryAug 27, 2008 - 3:21 p.m.

CVE-2008-3745

2008-08-2715:21:00
CWE-264
web.nvd.nist.gov
21
drupal
drupal 6.x
security vulnerability
authenticated users
node editing
file deletion

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.0%

The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.

Affected configurations

NVD
Node
drupaldrupalMatch6.0
OR
drupaldrupalMatch6.1
OR
drupaldrupalMatch6.2
OR
drupaldrupalMatch6.3
OR
drupalupload_module

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.0%