CVE-2008-4789
Published Oct 29, 2008
Last updated 7 years ago
Overview
- Description
- The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "522EC26C-B265-4A61-8751-0866EA735DCE", "versionEndIncluding": "6.4" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFE07AAD-9207-4C5F-A108-7F7753E4F48C" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4149703-F7BB-4513-9379-992C089532D1" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCBC7BB8-2B50-476D-BD96-C968F105CE10" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "550778E2-BEE5-403D-8744-0B18C5D3AFF3" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31B9F954-3A10-4378-A842-4061E97056DE" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7954FAA5-0455-407F-B16F-CB1FD24F9FB5" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B254CD4E-51A2-4E8D-9B59-FA5610F76683" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4DF0926-E487-4F3B-B85B-2690127FE1FA" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D05C77D9-E816-41A6-80DB-F4815980A83C" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52D8F291-CBEB-4EAA-9388-F63066A2DFA0" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0BD5AEC-F20E-4E53-AF3F-2C60BA2D2171" }, { "criteria": "cpe:2.3:a:drupal:drupal:6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5D76BC5-0409-4D78-8064-A78B923E9167" } ], "operator": "OR" } ] } ]