5
CVE-2010-4775
- EPSS 0.6%
- Veröffentlicht 23.03.2011 22:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nicholas Thompson ≫ Relevant Content Version5.x-1.0
Nicholas Thompson ≫ Relevant Content Version5.x-1.1
Nicholas Thompson ≫ Relevant Content Version5.x-1.2
Nicholas Thompson ≫ Relevant Content Version5.x-1.3
Nicholas Thompson ≫ Relevant Content Version5.x-1.x-dev
Nicholas Thompson ≫ Relevant Content Version6.x-1.0
Nicholas Thompson ≫ Relevant Content Version6.x-1.1
Nicholas Thompson ≫ Relevant Content Version6.x-1.2
Nicholas Thompson ≫ Relevant Content Version6.x-1.3
Nicholas Thompson ≫ Relevant Content Version6.x-1.4
Nicholas Thompson ≫ Relevant Content Version6.x-1.x-dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.684 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.