6.8

CVE-2012-2721

Exploit
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moshe Weitzman ≫ Organic Groups Version 6.x-2.0
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.1
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.2
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.3
   Drupal ≫ Drupal Version -
Moshe Weitzman ≫ Organic Groups Version 6.x-2.x Update dev
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.6% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/06/14/3
http://drupal.org/node/1619736
Patch
http://drupal.org/node/1619810
Patch
Vendor Advisory
http://drupalcode.org/project/og.git/commitdiff/1485708
Patch
Exploit
http://secunia.com/advisories/49397
Vendor Advisory
http://www.osvdb.org/82728
http://www.securityfocus.com/bid/53838
https://exchange.xforce.ibmcloud.com/vulnerabilities/76150