CVE-2008-3000
https://notcve.org/view.php?id=CVE-2008-3000
The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions. El módulo Aggregation 5.x versiones anteriores a 5.x-4.4 para Drupal, nodo de acceso cuando se utilizan los módulos, no implementa apropiadamente el control de acceso, lo cual permite a atacantes remotos evitar restricciones previstas. • http://drupal.org/node/269479 http://secunia.com/advisories/30618 http://www.securityfocus.com/bid/29677 https://exchange.xforce.ibmcloud.com/vulnerabilities/43017 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2008-3001
https://notcve.org/view.php?id=CVE-2008-3001
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions. El módulo Aggregation 5.x versiones anteriores a 5.x-4.4 para Drupal permite a atacantes remotos subir ficheros con extensiones de su elección, y posiblemente ejecutar código de su elección, a través de una fuente RSS manipulada que permite subir ficheros con extensiones arbitrarias. • http://drupal.org/node/269479 http://secunia.com/advisories/30618 http://www.securityfocus.com/bid/29677 https://exchange.xforce.ibmcloud.com/vulnerabilities/43011 • CWE-94: Improper Control of Generation of Code ('Code Injection') •