5
CVE-2010-4775
- EPSS 1.49%
- Veröffentlicht 23.03.2011 22:00:02
- Zuletzt bearbeitet 16.06.2026 23:25:31
- Erkennungen
The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nicholas Thompson ≫ Relevant Content Version 5.x-1.0
Nicholas Thompson ≫ Relevant Content Version 5.x-1.1
Nicholas Thompson ≫ Relevant Content Version 5.x-1.2
Nicholas Thompson ≫ Relevant Content Version 5.x-1.3
Nicholas Thompson ≫ Relevant Content Version 5.x-1.x-dev
Nicholas Thompson ≫ Relevant Content Version 6.x-1.0
Nicholas Thompson ≫ Relevant Content Version 6.x-1.1
Nicholas Thompson ≫ Relevant Content Version 6.x-1.2
Nicholas Thompson ≫ Relevant Content Version 6.x-1.3
Nicholas Thompson ≫ Relevant Content Version 6.x-1.4
Nicholas Thompson ≫ Relevant Content Version 6.x-1.x-dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.49% | 0.707 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://drupal.org/node/974668
http://drupal.org/node/974672
http://drupal.org/node/975094
http://osvdb.org/69368
http://secunia.com/advisories/42228
http://www.securityfocus.com/bid/44932
https://exchange.xforce.ibmcloud.com/vulnerabilities/63331