CVE-2008-1729
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.
El menú de sistema en Drupal 6 anterior a 6.2 tiene configuraciones de menu incorrectas, que permiten a atacantes remotos (1) editar las páginas de perfil de usuarios a su elección, y obtener información sensible del (2) rastreador y (3) páginas de blog, relacionados con falta de comprobaciones de los permisos de "acceso a contenidos"; y (4) permite autenticación de usuarios remotos, con acceso a página de administración, para editar tipos de contenidos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-11 CVE Reserved
- 2008-04-11 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/29762 | Third Party Advisory | |
http://www.osvdb.org/44270 | Broken Link | |
http://www.vupen.com/english/advisories/2008/1185/references | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41755 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/244637 | 2021-04-19 | |
http://www.securityfocus.com/bid/28714 | 2021-04-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | >= 6.0 < 6.2 Search vendor "Drupal" for product "Drupal" and version " >= 6.0 < 6.2" | - |
Affected
|