2.1

CVE-2012-5586

The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Marc Ingram ≫ Services Version 6.x-3.0
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update alpha1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update beta1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update beta2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update rc1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update rc2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update rc3
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update rc4
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update unstable1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update unstable2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.0 Update unstable3
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 6.x-3.x Update dev
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update beta1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update beta2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update rc1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update rc2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update rc3
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update rc4
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update rc5
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.0 Update rc6
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.1
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.2
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.3
   Drupal ≫ Drupal Version -
Marc Ingram ≫ Services Version 7.x-3.x Update dev
   Drupal ≫ Drupal Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.96% 0.568
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:N/AC:H/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/11/29/2
http://drupal.org/node/1842022
Patch
http://drupal.org/node/1842026
Patch
http://drupal.org/node/1853200
Patch
Vendor Advisory
http://www.securityfocus.com/bid/56723