Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-3169

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal7fixed7.43-1package
drupal6removedpackage
drupal6end-of-lifesqueezepackage

Примечания

  • https://www.drupal.org/SA-CORE-2016-001

  • https://www.openwall.com/lists/oss-security/2016/02/24/19

EPSS

Процентиль: 76%
0.01016
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 9 лет назад

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.

CVSS3: 8.1
nvd
около 9 лет назад

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.

CVSS3: 8.1
github
около 3 лет назад

Drupal saving user accounts can sometimes grant the user all roles

EPSS

Процентиль: 76%
0.01016
Низкий
Уязвимость CVE-2016-3169