7.5
CVE-2008-6908
- EPSS 0.66%
- Veröffentlicht 06.08.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Marc Ingram ≫ Services Version5.x-0.9
Marc Ingram ≫ Services Version5.x-0.91
Marc Ingram ≫ Services Version5.x-1.x-dev
Marc Ingram ≫ Services Version6.x-0.9
Marc Ingram ≫ Services Version6.x-0.11
Marc Ingram ≫ Services Version6.x-0.12
Marc Ingram ≫ Services Version6.x-1.x-dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.703 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|