Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-4792

Опубликовано: 29 окт. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 6

Описание

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

РелизСтатусПримечание
dapper

DNE

devel

DNE

gutsy

ignored

end of life, was needed
hardy

released

5.7-1ubuntu1.2
intrepid

released

5.10-1ubuntu1.1
jaunty

not-affected

5.15-1ubuntu1
karmic

not-affected

5.18-1.1ubuntu2
upstream

released

5.11

Показывать по

6 Medium

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

debian
больше 16 лет назад

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 d ...

github
около 3 лет назад

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

6 Medium

CVSS2