5
CVE-2012-4471
- EPSS 1.33%
- Veröffentlicht 30.11.2012 22:55:00
- Zuletzt bearbeitet 16.06.2026 23:45:09
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dominique Clause ≫ Search Autocomplete Version7.x-2.0
Dominique Clause ≫ Search Autocomplete Version7.x-2.1
Dominique Clause ≫ Search Autocomplete Version7.x-2.3
Dominique Clause ≫ Search Autocomplete Version7.x-2.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.33% | 0.674 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://www.openwall.com/lists/oss-security/2012/10/04/3
http://drupal.org/node/1649442
http://drupal.org/node/1679422
http://www.securityfocus.com/bid/54379