4
CVE-2012-4495
- EPSS 0.36%
- Veröffentlicht 31.10.2012 16:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mime Mail Module Project ≫ Mimemail Version6.x-1.0
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha1
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha2
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha3
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha4
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha5
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha6
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha7
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatealpha8
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatebeta1
Mime Mail Module Project ≫ Mimemail Version6.x-1.0 Updatebeta2
Mime Mail Module Project ≫ Mimemail Version6.x-1.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.554 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|