CVE-2012-4488
Published Oct 31, 2012
Last updated 12 years ago
Overview
- Description
- The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows remote attackers to read node or user results via the location search page.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D1698DC-E5F7-4551-8733-22D0C6DBC7EF" }, { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BD4F5FF-AB94-4BB6-ADFD-95A04C243493" }, { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C370E871-839F-4BC8-8DF1-6CCD828AC238" }, { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.0:test3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "653AB041-6093-4908-9EBF-59AA96F77470" }, { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FECCAEC1-037D-42FA-A531-3E7B414976D3" }, { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.1:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFD761E9-EF45-4589-9F9E-755168470736" }, { "criteria": "cpe:2.3:a:location_module_project:location:6.x-3.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F7B570F-A43D-43A7-848A-3730EB4680B8" }, { "criteria": "cpe:2.3:a:location_module_project:location:7.x-1.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46387A3E-D446-4BFA-A657-9730492759CD" }, { "criteria": "cpe:2.3:a:location_module_project:location:7.x-3.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88718278-C458-4607-A4E9-A4FE3F8DAC72" }, { "criteria": "cpe:2.3:a:location_module_project:location:7.x-4.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7789237-66FE-4766-93B0-6EDFA221A840" }, { "criteria": "cpe:2.3:a:location_module_project:location:7.x-5.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39F1AB98-AD33-4D6A-8E95-E750D3EB65FC" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF" } ], "operator": "OR" } ], "operator": "AND" } ]