Логотип exploitDog
bind:CVE-2013-4445
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-4445

Количество 2

Количество 2

nvd логотип

CVE-2013-4445

больше 11 лет назад

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

CVSS2: 4.9
EPSS: Низкий
github логотип

GHSA-86q5-5pcw-rm5q

около 3 лет назад

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2013-4445

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

CVSS2: 4.9
1%
Низкий
больше 11 лет назад
github логотип
GHSA-86q5-5pcw-rm5q

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

1%
Низкий
около 3 лет назад

Уязвимостей на страницу