2 results (0.005 seconds)

CVSS: 6.8EPSS: 0%CPEs: 8EXPL: 0

The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions. El módulo Aggregation 5.x versiones anteriores a 5.x-4.4 para Drupal, nodo de acceso cuando se utilizan los módulos, no implementa apropiadamente el control de acceso, lo cual permite a atacantes remotos evitar restricciones previstas. • http://drupal.org/node/269479 http://secunia.com/advisories/30618 http://www.securityfocus.com/bid/29677 https://exchange.xforce.ibmcloud.com/vulnerabilities/43017 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.3EPSS: 4%CPEs: 8EXPL: 0

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions. El módulo Aggregation 5.x versiones anteriores a 5.x-4.4 para Drupal permite a atacantes remotos subir ficheros con extensiones de su elección, y posiblemente ejecutar código de su elección, a través de una fuente RSS manipulada que permite subir ficheros con extensiones arbitrarias. • http://drupal.org/node/269479 http://secunia.com/advisories/30618 http://www.securityfocus.com/bid/29677 https://exchange.xforce.ibmcloud.com/vulnerabilities/43011 • CWE-94: Improper Control of Generation of Code ('Code Injection') •