6

CVE-2007-0506

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Project Version 4.6
Drupal ≫ Project Version 4.6_1.1
Drupal ≫ Project Version 4.7
Drupal ≫ Project Version 4.7_1.1
Drupal ≫ Project Version 4.7_2.1
Drupal ≫ Project Version 5.0 Edition dev
Drupal ≫ Project Issue Tracking Module Version 5.0 Edition dev
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.12% 0.619
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://drupal.org/node/112146
Patch
Vendor Advisory
http://secunia.com/advisories/23887
http://www.securityfocus.com/bid/22224
http://www.vupen.com/english/advisories/2007/0312
http://osvdb.org/32135
https://exchange.xforce.ibmcloud.com/vulnerabilities/31727