Lucene search

K
cveMitreCVE-2014-9024
HistoryNov 20, 2014 - 5:50 p.m.

CVE-2014-9024

2014-11-2017:50:13
CWE-264
mitre
web.nvd.nist.gov
20
cve-2014-9024
drupal
vulnerability
remote attack
password bypass

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.007

Percentile

80.0%

The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path.

Affected configurations

Nvd
Node
protected_pages_projectprotected_pagesMatch7.x-1.0drupal
OR
protected_pages_projectprotected_pagesMatch7.x-2.0drupal
OR
protected_pages_projectprotected_pagesMatch7.x-2.2drupal
VendorProductVersionCPE
protected_pages_projectprotected_pages7.x-1.0cpe:2.3:a:protected_pages_project:protected_pages:7.x-1.0:*:*:*:*:drupal:*:*
protected_pages_projectprotected_pages7.x-2.0cpe:2.3:a:protected_pages_project:protected_pages:7.x-2.0:*:*:*:*:drupal:*:*
protected_pages_projectprotected_pages7.x-2.2cpe:2.3:a:protected_pages_project:protected_pages:7.x-2.2:*:*:*:*:drupal:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.007

Percentile

80.0%

Related for CVE-2014-9024