5
CVE-2012-4488
- EPSS 1.37%
- Veröffentlicht 31.10.2012 16:55:03
- Zuletzt bearbeitet 16.06.2026 23:45:11
- Erkennungen
The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote attackers to read node or user results via the location search page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Location Module Project ≫ Location Version 6.x-3.0
Location Module Project ≫ Location Version 6.x-3.0 Update rc1
Location Module Project ≫ Location Version 6.x-3.0 Update rc2
Location Module Project ≫ Location Version 6.x-3.0 Update test3
Location Module Project ≫ Location Version 6.x-3.1
Location Module Project ≫ Location Version 6.x-3.1 Update rc1
Location Module Project ≫ Location Version 6.x-3.x Update dev
Location Module Project ≫ Location Version 7.x-1.0 Update beta1
Location Module Project ≫ Location Version 7.x-3.x Update dev
Location Module Project ≫ Location Version 7.x-4.x Update dev
Location Module Project ≫ Location Version 7.x-5.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.37% | 0.683 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://www.openwall.com/lists/oss-security/2012/10/04/6
http://www.openwall.com/lists/oss-security/2012/10/07/1
http://drupal.org/node/1699962
http://drupal.org/node/1699984
http://drupal.org/node/1700588