3.5

CVE-2009-3782

Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
2bitsUserpoints Version6.x-1.0
   DrupalDrupal
2bitsUserpoints Version6.x-1.x-dev
   DrupalDrupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://drupal.org/node/610818
Patch
Vendor Advisory
http://drupal.org/node/610828
Patch
Vendor Advisory
http://osvdb.org/59124
http://secunia.com/advisories/37123
Vendor Advisory
http://www.securityfocus.com/bid/36786
Patch
http://www.vupen.com/english/advisories/2009/2998
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53896