// For flags

CVE-2013-1946

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."

El módulo RESTful Web Services (RESTWS) 7.x-1.x anterior a 7.x-1.3 y 7.x-2.x anterior a 7.x-2.0-alpha5 para Drupal, cuando el cacheo de la página está habilitado y usuarios anónimos se les asignan permisos RESTWS, permite a atacantes remotos causar una denegación de servicio a través de una solicitud GET con una cabecera HTTP Accept configurada hacia un tipo no HTML, lo que puede "interferir con el cacheo de página de Drupal."

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-02-19 CVE Reserved
  • 2014-04-06 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Restful Web Services Project
Search vendor "Restful Web Services Project"
Restful Web Services
Search vendor "Restful Web Services Project" for product "Restful Web Services"
7.x-1.1
Search vendor "Restful Web Services Project" for product "Restful Web Services" and version "7.x-1.1"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Restful Web Services Project
Search vendor "Restful Web Services Project"
Restful Web Services
Search vendor "Restful Web Services Project" for product "Restful Web Services"
7.x-1.2
Search vendor "Restful Web Services Project" for product "Restful Web Services" and version "7.x-1.2"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Restful Web Services Project
Search vendor "Restful Web Services Project"
Restful Web Services
Search vendor "Restful Web Services Project" for product "Restful Web Services"
7.x-2.0
Search vendor "Restful Web Services Project" for product "Restful Web Services" and version "7.x-2.0"
alpha3
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe
Restful Web Services Project
Search vendor "Restful Web Services Project"
Restful Web Services
Search vendor "Restful Web Services Project" for product "Restful Web Services"
7.x-2.0
Search vendor "Restful Web Services Project" for product "Restful Web Services" and version "7.x-2.0"
alpha4
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
--
Safe