Lucene search

K
cveRedhatCVE-2012-2341
HistoryMay 18, 2012 - 10:55 p.m.

CVE-2012-2341

2012-05-1822:55:06
CWE-352
redhat
web.nvd.nist.gov
27
cve-2012-2341
csrf
take control module
drupal
ajax requests
file manipulation
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.003

Percentile

71.0%

Cross-site request forgery (CSRF) vulnerability in the Take Control module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to hijack the authentication of unspecified users for Ajax requests that manipulate files.

Affected configurations

Nvd
Node
rahul_singlatake_controlMatch6.x-1.x
OR
rahul_singlatake_controlMatch6.x-2.0beta3
OR
rahul_singlatake_controlMatch6.x-2.x
AND
drupaldrupal
VendorProductVersionCPE
rahul_singlatake_control6.x-1.xcpe:2.3:a:rahul_singla:take_control:6.x-1.x:*:*:*:*:*:*:*
rahul_singlatake_control6.x-2.0cpe:2.3:a:rahul_singla:take_control:6.x-2.0:beta3:*:*:*:*:*:*
rahul_singlatake_control6.x-2.xcpe:2.3:a:rahul_singla:take_control:6.x-2.x:*:*:*:*:*:*:*
drupaldrupal*cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.003

Percentile

71.0%

Related for CVE-2012-2341