2.1

CVE-2012-5586

The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to the user resource."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Marc IngramServices Version6.x-3.0
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updatealpha1
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updatebeta1
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updatebeta2
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updaterc1
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updaterc2
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updaterc3
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updaterc4
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updateunstable1
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updateunstable2
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.0 Updateunstable3
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.1
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.2
   DrupalDrupal Version-
Marc IngramServices Version6.x-3.x Updatedev
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updatebeta1
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updatebeta2
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updaterc1
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updaterc2
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updaterc3
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updaterc4
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updaterc5
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.0 Updaterc6
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.1
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.2
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.3
   DrupalDrupal Version-
Marc IngramServices Version7.x-3.x Updatedev
   DrupalDrupal Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.456
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:N/AC:H/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.