5

CVE-2009-3568

Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dave ReidCommentrss Version5.x-2.1
   DrupalDrupal
Dave ReidCommentrss Version6.x-2.1
   DrupalDrupal
Gabor HojtsyCommentrss Version5.x-1.0
   DrupalDrupal
Gabor HojtsyCommentrss Version5.x-1.1
   DrupalDrupal
Gabor HojtsyCommentrss Version5.x-1.2
   DrupalDrupal
Gabor HojtsyCommentrss Version5.x-1.x Updatedev
   DrupalDrupal
Gabor HojtsyCommentrss Version5.x-2.0
   DrupalDrupal
Gabor HojtsyCommentrss Version5.x-2.x Updatedev
   DrupalDrupal
Gabor HojtsyCommentrss Version6.x-1.0
   DrupalDrupal
Gabor HojtsyCommentrss Version6.x-1.1
   DrupalDrupal
Gabor HojtsyCommentrss Version6.x-1.2
   DrupalDrupal
Gabor HojtsyCommentrss Version6.x-2.0
   DrupalDrupal
Gabor HojtsyCommentrss Version6.x-2.x Updatedev
   DrupalDrupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.44% 0.698
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://drupal.org/node/579280
Patch
Vendor Advisory
http://drupal.org/node/579290
Patch
Vendor Advisory
http://drupal.org/node/579292
Patch
Vendor Advisory
http://secunia.com/advisories/36787
Vendor Advisory
http://www.osvdb.org/58177
http://www.securityfocus.com/bid/36429