Lucene search

K
cve[email protected]CVE-2008-4790
HistoryOct 29, 2008 - 3:31 p.m.

CVE-2008-4790

2008-10-2915:31:35
CWE-264
web.nvd.nist.gov
20
drupal
cve-2008-4790
upload module
remote authenticated users
access restrictions

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.3%

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read “files attached to content” via unknown vectors.

Affected configurations

NVD
Node
drupaldrupalRange5.10
OR
drupaldrupalMatch5.0
OR
drupaldrupalMatch5.0beta1
OR
drupaldrupalMatch5.0beta2
OR
drupaldrupalMatch5.0rc1
OR
drupaldrupalMatch5.0rc2
OR
drupaldrupalMatch5.1
OR
drupaldrupalMatch5.2
OR
drupaldrupalMatch5.3
OR
drupaldrupalMatch5.4
OR
drupaldrupalMatch5.5
OR
drupaldrupalMatch5.6
OR
drupaldrupalMatch5.7
OR
drupaldrupalMatch5.8
OR
drupaldrupalMatch5.9

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

68.3%