Lucene search

K
cveMitreCVE-2009-3784
HistoryOct 26, 2009 - 5:30 p.m.

CVE-2009-3784

2009-10-2617:30:00
CWE-352
mitre
web.nvd.nist.gov
29
cve-2009-3784
open redirect vulnerability
simplenews statistics
drupal
remote attackers
phishing attacks
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

60.8%

Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Affected configurations

Nvd
Node
drupaldrupal
AND
sjoerd_arendsensimplenews_statisticsMatch6.x-1.0
OR
sjoerd_arendsensimplenews_statisticsMatch6.x-1.1
OR
sjoerd_arendsensimplenews_statisticsMatch6.x-1.2
OR
sjoerd_arendsensimplenews_statisticsMatch6.x-1.x-dev
VendorProductVersionCPE
drupaldrupal*cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
sjoerd_arendsensimplenews_statistics6.x-1.0cpe:2.3:a:sjoerd_arendsen:simplenews_statistics:6.x-1.0:*:*:*:*:*:*:*
sjoerd_arendsensimplenews_statistics6.x-1.1cpe:2.3:a:sjoerd_arendsen:simplenews_statistics:6.x-1.1:*:*:*:*:*:*:*
sjoerd_arendsensimplenews_statistics6.x-1.2cpe:2.3:a:sjoerd_arendsen:simplenews_statistics:6.x-1.2:*:*:*:*:*:*:*
sjoerd_arendsensimplenews_statistics6.x-1.x-devcpe:2.3:a:sjoerd_arendsen:simplenews_statistics:6.x-1.x-dev:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

60.8%

Related for CVE-2009-3784