6
CVE-2012-1650
- EPSS 1.2%
- Veröffentlicht 28.08.2012 17:55:04
- Zuletzt bearbeitet 16.06.2026 23:40:00
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Giantrobot ≫ Zipcart Version6.x-1.2
Giantrobot ≫ Zipcart Version6.x-1.3
Giantrobot ≫ Zipcart Version6.x-1.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.642 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
http://www.openwall.com/lists/oss-security/2012/04/07/1
https://drupal.org/node/1460892
http://drupalcode.org/project/zipcart.git/commitdiff/fe143c2
http://www.osvdb.org/79766
http://www.securityfocus.com/bid/52231
https://drupal.org/node/1461446
https://exchange.xforce.ibmcloud.com/vulnerabilities/73609