7.5
CVE-2012-2303
- EPSS 1.96%
- Veröffentlicht 18.07.2012 18:55:03
- Zuletzt bearbeitet 16.06.2026 23:41:19
- Erkennungen
The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Florian Weber ≫ Spaces Version 6.x-3.0
Florian Weber ≫ Spaces Version 6.x-3.0 Update alpha1
Florian Weber ≫ Spaces Version 6.x-3.0 Update alpha2
Florian Weber ≫ Spaces Version 6.x-3.0 Update beta1
Florian Weber ≫ Spaces Version 6.x-3.0 Update beta2
Florian Weber ≫ Spaces Version 6.x-3.0 Update beta3
Florian Weber ≫ Spaces Version 6.x-3.0 Update beta4
Florian Weber ≫ Spaces Version 6.x-3.0 Update beta5
Florian Weber ≫ Spaces Version 6.x-3.0 Update beta6
Florian Weber ≫ Spaces Version 6.x-3.0 Update r1
Florian Weber ≫ Spaces Version 6.x-3.0 Update r2
Florian Weber ≫ Spaces Version 6.x-3.1
Florian Weber ≫ Spaces Version 6.x-3.2
Florian Weber ≫ Spaces Version 6.x-3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.96% | 0.777 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://drupal.org/node/1547730
http://drupal.org/node/1547736
http://drupalcode.org/project/spaces.git/commitdiff/cee919c
http://secunia.com/advisories/48930
http://www.openwall.com/lists/oss-security/2012/05/03/1
http://www.openwall.com/lists/oss-security/2012/05/03/2
http://www.osvdb.org/81556
http://www.securityfocus.com/bid/53252