Lucene search

K
cve[email protected]CVE-2008-4789
HistoryOct 29, 2008 - 3:31 p.m.

CVE-2008-4789

2008-10-2915:31:35
CWE-264
web.nvd.nist.gov
18
drupal
upload module
validation functionality
cve-2008-4789
access restrictions

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.0%

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and “attach files to content,” related to a “logic error.”

Affected configurations

NVD
Node
drupaldrupalRange6.4
OR
drupaldrupalMatch6.0
OR
drupaldrupalMatch6.0beta1
OR
drupaldrupalMatch6.0beta2
OR
drupaldrupalMatch6.0beta3
OR
drupaldrupalMatch6.0beta4
OR
drupaldrupalMatch6.0rc-1
OR
drupaldrupalMatch6.0rc-2
OR
drupaldrupalMatch6.0rc-3
OR
drupaldrupalMatch6.0rc-4
OR
drupaldrupalMatch6.1
OR
drupaldrupalMatch6.2
OR
drupaldrupalMatch6.3

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.0%

Related for CVE-2008-4789