Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4495

Опубликовано: 31 окт. 2012
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:alpha8:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:mime_mail_module_project:mimemail:6.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00364
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
около 3 лет назад

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

EPSS

Процентиль: 58%
0.00364
Низкий

4 Medium

CVSS2

Дефекты

CWE-264