6.4
CVE-2013-1859
- EPSS 2.75%
- Veröffentlicht 27.03.2013 21:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chris Desautels ≫ Node Parameter Control Version6.x-1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.75% | 0.843 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://drupal.org/node/1942330
http://osvdb.org/91257
http://packetstormsecurity.com/files/120788/Drupal-Node-Parameter-Control-6.x-Access-Bypass.html
http://seclists.org/fulldisclosure/2013/Mar/133
http://www.openwall.com/lists/oss-security/2013/03/15/2