Lucene search

K
cveMitreCVE-2015-8761
HistoryJan 08, 2016 - 7:59 p.m.

CVE-2015-8761

2016-01-0819:59:27
CWE-94
mitre
web.nvd.nist.gov
25
cve-2015-8761
drupal
values module
remote code execution
permissions
nvd

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.4%

The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the “Import value sets” permission to execute arbitrary PHP code via the exported values list in a ctools import.

Affected configurations

Nvd
Node
values_projectvaluesMatch7.x-1.0drupal
OR
values_projectvaluesMatch7.x-1.0beta1drupal
OR
values_projectvaluesMatch7.x-1.0beta2drupal
OR
values_projectvaluesMatch7.x-1.0beta3drupal
OR
values_projectvaluesMatch7.x-1.0rc1drupal
OR
values_projectvaluesMatch7.x-1.0rc2drupal
OR
values_projectvaluesMatch7.x-1.0rc3drupal
OR
values_projectvaluesMatch7.x-1.0rc4drupal
OR
values_projectvaluesMatch7.x-1.0rc5drupal
OR
values_projectvaluesMatch7.x-1.1drupal
VendorProductVersionCPE
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:*:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:beta1:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:beta2:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:beta3:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:rc1:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:rc2:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:rc3:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:rc4:*:*:*:drupal:*:*
values_projectvalues7.x-1.0cpe:2.3:a:values_project:values:7.x-1.0:rc5:*:*:*:drupal:*:*
values_projectvalues7.x-1.1cpe:2.3:a:values_project:values:7.x-1.1:*:*:*:*:drupal:*:*

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

57.4%

Related for CVE-2015-8761