2.1
CVE-2012-5586
- EPSS 0.25%
- Veröffentlicht 26.12.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Marc Ingram ≫ Services Version6.x-3.0
Marc Ingram ≫ Services Version6.x-3.0 Updatealpha1
Marc Ingram ≫ Services Version6.x-3.0 Updatebeta1
Marc Ingram ≫ Services Version6.x-3.0 Updatebeta2
Marc Ingram ≫ Services Version6.x-3.0 Updaterc1
Marc Ingram ≫ Services Version6.x-3.0 Updaterc2
Marc Ingram ≫ Services Version6.x-3.0 Updaterc3
Marc Ingram ≫ Services Version6.x-3.0 Updaterc4
Marc Ingram ≫ Services Version6.x-3.0 Updateunstable1
Marc Ingram ≫ Services Version6.x-3.0 Updateunstable2
Marc Ingram ≫ Services Version6.x-3.0 Updateunstable3
Marc Ingram ≫ Services Version6.x-3.1
Marc Ingram ≫ Services Version6.x-3.2
Marc Ingram ≫ Services Version6.x-3.x Updatedev
Marc Ingram ≫ Services Version7.x-3.0
Marc Ingram ≫ Services Version7.x-3.0 Updatebeta1
Marc Ingram ≫ Services Version7.x-3.0 Updatebeta2
Marc Ingram ≫ Services Version7.x-3.0 Updaterc1
Marc Ingram ≫ Services Version7.x-3.0 Updaterc2
Marc Ingram ≫ Services Version7.x-3.0 Updaterc3
Marc Ingram ≫ Services Version7.x-3.0 Updaterc4
Marc Ingram ≫ Services Version7.x-3.0 Updaterc5
Marc Ingram ≫ Services Version7.x-3.0 Updaterc6
Marc Ingram ≫ Services Version7.x-3.1
Marc Ingram ≫ Services Version7.x-3.2
Marc Ingram ≫ Services Version7.x-3.3
Marc Ingram ≫ Services Version7.x-3.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.456 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:P/I:N/A:N
|