Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3379

Опубликовано: 21 апр. 2015
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:views_project:views:*:*:*:*:*:drupal:*:*
Версия до 6.x-2.16 (включая)
cpe:2.3:a:views_project:views:6.x-3.0:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:6.x-3.0:alpha1:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:6.x-3.0:alpha2:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:6.x-3.0:alpha3:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:6.x-3.0:alpha4:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:6.x-3.0:rc2:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:6.x-3.0:rc3:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:alpha1:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:beta1:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:beta2:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:beta3:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:rc1:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.0:rc3:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.1:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.2:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.3:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.4:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.5:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.6:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.7:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.8:*:*:*:*:drupal:*:*
cpe:2.3:a:views_project:views:7.x-3.x:dev:*:*:*:drupal:*:*

EPSS

Процентиль: 48%
0.00251
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

EPSS

Процентиль: 48%
0.00251
Низкий

4 Medium

CVSS2

Дефекты

CWE-264