Lucene search

K
cveRedhatCVE-2012-4491
HistoryOct 31, 2012 - 4:55 p.m.

CVE-2012-4491

2012-10-3116:55:03
CWE-264
redhat
web.nvd.nist.gov
20
cve-2012-4491
monthly archive
node type
drupal
permission check vulnerability
remote access

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

70.7%

The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attackers to access restricted nodes via unspecified vectors.

Affected configurations

Nvd
Node
earl_dunovantmonthly_archive_by_node_typeMatch6.x-1.0
OR
earl_dunovantmonthly_archive_by_node_typeMatch6.x-2.0
OR
earl_dunovantmonthly_archive_by_node_typeMatch6.x-3.0
AND
drupaldrupalMatch-
VendorProductVersionCPE
earl_dunovantmonthly_archive_by_node_type6.x-1.0cpe:2.3:a:earl_dunovant:monthly_archive_by_node_type:6.x-1.0:*:*:*:*:*:*:*
earl_dunovantmonthly_archive_by_node_type6.x-2.0cpe:2.3:a:earl_dunovant:monthly_archive_by_node_type:6.x-2.0:*:*:*:*:*:*:*
earl_dunovantmonthly_archive_by_node_type6.x-3.0cpe:2.3:a:earl_dunovant:monthly_archive_by_node_type:6.x-3.0:*:*:*:*:*:*:*
drupaldrupal-cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

70.7%

Related for CVE-2012-4491