4

CVE-2012-4495

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha1
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha2
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha3
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha4
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha5
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha6
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha7
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update alpha8
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update beta1
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.0 Update beta2
   Drupal ≫ Drupal Version -
Mime Mail Module Project ≫ Mimemail Version 6.x-1.x Update dev
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.642
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/10/04/6
http://www.openwall.com/lists/oss-security/2012/10/07/1
http://drupal.org/node/1719446
Patch
http://drupal.org/node/1719482
Patch
Vendor Advisory
http://drupalcode.org/project/mimemail.git/commitdiff/ae065d1
http://www.securityfocus.com/bid/54914