4

CVE-2009-3921

The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node privileges in certain circumstances involving subqueue creation, which allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 5.x-1.0
   Drupal ≫ Drupal
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 5.x-1.1
   Drupal ≫ Drupal
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 5.x-1.2
   Drupal ≫ Drupal
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 5.x-1.x-dev
   Drupal ≫ Drupal
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 6.x-1.0 Update rc1
   Drupal ≫ Drupal
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 6.x-1.0 Update rc2
   Drupal ≫ Drupal
Ezra Barnett Gildesgame ≫ Smartqueue Og Version 6.x-1.x-dev
   Drupal ≫ Drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.15% 0.628
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://drupal.org/node/617496
Patch
Vendor Advisory
http://drupal.org/node/617500
Patch
Vendor Advisory
http://drupal.org/node/623554
Patch
Vendor Advisory
http://osvdb.org/59675
http://secunia.com/advisories/37288
Vendor Advisory
http://www.securityfocus.com/bid/36925
Patch