Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1729

Опубликовано: 11 апр. 2008
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Версия от 6.0 (включая) до 6.2 (исключая)

EPSS

Процентиль: 69%
0.00618
Низкий

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

github
около 3 лет назад

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

EPSS

Процентиль: 69%
0.00618
Низкий

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo