2.1

CVE-2012-2299

Exploit
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ubercart ≫ Ubercart Version 6.x-2.0
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta5
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update beta6
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update dev
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc5
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc6
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.0 Update rc7
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.6
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 6.x-2.7
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update alpha3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update beta4
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update dev
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc1
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc2
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc3
   Drupal ≫ Drupal Version -
Ubercart ≫ Ubercart Version 7.x-3.0 Update rc4
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.401
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/05/03/1
http://www.openwall.com/lists/oss-security/2012/05/03/2
http://drupal.org/node/1547506
Patch
http://drupal.org/node/1547508
Patch
http://drupal.org/node/1547674
Patch
Vendor Advisory
http://drupalcode.org/project/ubercart.git/commitdiff/035d2cb
Patch
Exploit
http://drupalcode.org/project/ubercart.git/commitdiff/8c61e84
Patch
Exploit
http://secunia.com/advisories/48935
Vendor Advisory
http://www.securityfocus.com/bid/53251