3.5

CVE-2009-3782

Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
2bits ≫ Userpoints Version 6.x-1.0
   Drupal ≫ Drupal
2bits ≫ Userpoints Version 6.x-1.x-dev
   Drupal ≫ Drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://drupal.org/node/610818
Patch
Vendor Advisory
http://drupal.org/node/610828
Patch
Vendor Advisory
http://osvdb.org/59124
http://secunia.com/advisories/37123
Vendor Advisory
http://www.securityfocus.com/bid/36786
Patch
http://www.vupen.com/english/advisories/2009/2998
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53896