// For flags

CVE-2013-0206

 

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

Vulnerabilidad de subida de archivos sin restricciones en el módulo CSS en vivo v6.x-2.x antes v6.x-2.1 y v7.x-2.x antes v7.x-2.7 para Drupal que permite a usuarios remotos autenticados con los privilegios "administer CSS" a ejecutar código arbitrario mediante la carga de un archivo con una extensión ejecutable, y luego acceder a ella a través de una solicitud dirigida directamente al archivo en un directorio especificado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-03-19 CVE Published
  • 2024-09-16 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
6.x-2.0
Search vendor "Guy Bedford" for product "Live Css" and version "6.x-2.0"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.0
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.0"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.0-beta1
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.0-beta1"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.1
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.1"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.2
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.2"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.3
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.3"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.4
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.4"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.5
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.5"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.6
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.6"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Guy Bedford
Search vendor "Guy Bedford"
Live Css
Search vendor "Guy Bedford" for product "Live Css"
7.x-2.x-dev
Search vendor "Guy Bedford" for product "Live Css" and version "7.x-2.x-dev"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe