Lucene search

K
cve[email protected]CVE-2013-4406
HistoryMay 19, 2014 - 2:55 p.m.

CVE-2013-4406

2014-05-1914:55:07
CWE-264
web.nvd.nist.gov
17
cve-2013-4406
drupal
quick tabs
information security
vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.6%

The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions, which allows remote attackers to obtain sensitive information by reading a Quick Tab.

Affected configurations

NVD
Node
quick_tabs_module_projectquicktabsMatch6.x-3.0-drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-3.0beta1drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-3.0beta2drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-3.1drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-3.xdevdrupal
Node
quick_tabs_module_projectquicktabsMatch7.x-3.0-drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.0alpha1drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.0alpha2drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.0beta1drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.0beta2drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.0beta3drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.1drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.2drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.3drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.4drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.5drupal
OR
quick_tabs_module_projectquicktabsMatch7.x-3.xdevdrupal
Node
quick_tabs_module_projectquicktabsMatch6.x-2.0-drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.0rc1drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.0rc2drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.0rc3drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.0rc4drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.0rc5drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.1drupal
OR
quick_tabs_module_projectquicktabsMatch6.x-2.xdevdrupal

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.6%

Related for CVE-2013-4406