6

CVE-2012-1650

The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GiantrobotZipcart Version6.x-1.2
   DrupalDrupal Version-
GiantrobotZipcart Version6.x-1.3
   DrupalDrupal Version-
GiantrobotZipcart Version6.x-1.x Updatedev
   DrupalDrupal Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.642
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/04/07/1
https://drupal.org/node/1460892
Patch
http://drupalcode.org/project/zipcart.git/commitdiff/fe143c2
Patch
http://www.osvdb.org/79766
http://www.securityfocus.com/bid/52231
https://drupal.org/node/1461446
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/73609