5
CVE-2010-4775
- EPSS 1.49%
- Veröffentlicht 23.03.2011 22:00:02
- Zuletzt bearbeitet 16.06.2026 23:25:31
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nicholas Thompson ≫ Relevant Content Version5.x-1.0
Nicholas Thompson ≫ Relevant Content Version5.x-1.1
Nicholas Thompson ≫ Relevant Content Version5.x-1.2
Nicholas Thompson ≫ Relevant Content Version5.x-1.3
Nicholas Thompson ≫ Relevant Content Version5.x-1.x-dev
Nicholas Thompson ≫ Relevant Content Version6.x-1.0
Nicholas Thompson ≫ Relevant Content Version6.x-1.1
Nicholas Thompson ≫ Relevant Content Version6.x-1.2
Nicholas Thompson ≫ Relevant Content Version6.x-1.3
Nicholas Thompson ≫ Relevant Content Version6.x-1.4
Nicholas Thompson ≫ Relevant Content Version6.x-1.x-dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.49% | 0.707 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://drupal.org/node/974668
http://drupal.org/node/974672
http://drupal.org/node/975094
http://osvdb.org/69368
http://secunia.com/advisories/42228
http://www.securityfocus.com/bid/44932
https://exchange.xforce.ibmcloud.com/vulnerabilities/63331