CVE-2012-1650
Published Aug 28, 2012
Last updated 7 years ago
Overview
- Description
- The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:giantrobot:zipcart:6.x-1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3290D7BF-1B55-4578-A833-2755F09FAD91" }, { "criteria": "cpe:2.3:a:giantrobot:zipcart:6.x-1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B938E14-6010-480E-9441-41DF01F1E4E2" }, { "criteria": "cpe:2.3:a:giantrobot:zipcart:6.x-1.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A065737E-47C5-4614-9AA1-4C4C58BBEDD8" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF" } ], "operator": "OR" } ], "operator": "AND" } ]