6
CVE-2012-1650
- EPSS 1.2%
- Veröffentlicht 28.08.2012 17:55:04
- Zuletzt bearbeitet 16.06.2026 23:40:00
- Erkennungen
The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Giantrobot ≫ Zipcart Version 6.x-1.2
Giantrobot ≫ Zipcart Version 6.x-1.3
Giantrobot ≫ Zipcart Version 6.x-1.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.642 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
http://www.openwall.com/lists/oss-security/2012/04/07/1
https://drupal.org/node/1460892
http://drupalcode.org/project/zipcart.git/commitdiff/fe143c2
http://www.osvdb.org/79766
http://www.securityfocus.com/bid/52231
https://drupal.org/node/1461446
https://exchange.xforce.ibmcloud.com/vulnerabilities/73609