2.1
CVE-2012-5586
- EPSS 0.96%
- Veröffentlicht 26.12.2012 17:55:02
- Zuletzt bearbeitet 16.06.2026 23:47:03
- Erkennungen
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Marc Ingram ≫ Services Version 6.x-3.0
Marc Ingram ≫ Services Version 6.x-3.0 Update alpha1
Marc Ingram ≫ Services Version 6.x-3.0 Update beta1
Marc Ingram ≫ Services Version 6.x-3.0 Update beta2
Marc Ingram ≫ Services Version 6.x-3.0 Update rc1
Marc Ingram ≫ Services Version 6.x-3.0 Update rc2
Marc Ingram ≫ Services Version 6.x-3.0 Update rc3
Marc Ingram ≫ Services Version 6.x-3.0 Update rc4
Marc Ingram ≫ Services Version 6.x-3.0 Update unstable1
Marc Ingram ≫ Services Version 6.x-3.0 Update unstable2
Marc Ingram ≫ Services Version 6.x-3.0 Update unstable3
Marc Ingram ≫ Services Version 6.x-3.1
Marc Ingram ≫ Services Version 6.x-3.2
Marc Ingram ≫ Services Version 6.x-3.x Update dev
Marc Ingram ≫ Services Version 7.x-3.0
Marc Ingram ≫ Services Version 7.x-3.0 Update beta1
Marc Ingram ≫ Services Version 7.x-3.0 Update beta2
Marc Ingram ≫ Services Version 7.x-3.0 Update rc1
Marc Ingram ≫ Services Version 7.x-3.0 Update rc2
Marc Ingram ≫ Services Version 7.x-3.0 Update rc3
Marc Ingram ≫ Services Version 7.x-3.0 Update rc4
Marc Ingram ≫ Services Version 7.x-3.0 Update rc5
Marc Ingram ≫ Services Version 7.x-3.0 Update rc6
Marc Ingram ≫ Services Version 7.x-3.1
Marc Ingram ≫ Services Version 7.x-3.2
Marc Ingram ≫ Services Version 7.x-3.3
Marc Ingram ≫ Services Version 7.x-3.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.96% | 0.568 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:P/I:N/A:N
|
http://www.openwall.com/lists/oss-security/2012/11/29/2
http://drupal.org/node/1842022
http://drupal.org/node/1842026
http://drupal.org/node/1853200
http://www.securityfocus.com/bid/56723