6.4

CVE-2005-3974

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

Data is provided by the National Vulnerability Database (NVD)
DrupalDrupal Version4.5
DrupalDrupal Version4.5.1
DrupalDrupal Version4.5.2
DrupalDrupal Version4.5.3
DrupalDrupal Version4.5.4
DrupalDrupal Version4.5.5
DrupalDrupal Version4.6
DrupalDrupal Version4.6.1
DrupalDrupal Version4.6.2
DrupalDrupal Version4.6.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.55% 0.652
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N