5
CVE-2008-2271
- EPSS 0.75%
- Veröffentlicht 16.05.2008 12:54:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Site Documentation Project ≫ Site Documentation SwPlatformdrupal Version >= 5.x-1.0 < 5.x-1.8
Site Documentation Project ≫ Site Documentation SwPlatformdrupal Version >= 6.x-1.0 < 6.x-1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.75% | 0.708 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.