CVE-2015-4393
Published Jun 15, 2015
Last updated 8 years ago
Overview
- Description
- The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6
- Impact score
- 6.4
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:services_project:services:7.x-3.0:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "8507487C-B934-480A-8D10-24C371D46EFF" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.1:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "EC965146-8BA9-4786-B2D7-0A63DBFFB022" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.2:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "7584BE36-CA24-4566-8982-DEAA90FFE059" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.3:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "002452ED-3758-4D10-8B23-63B632CEFF1B" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.4:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "96926BC8-2502-4EFB-BAD2-B03DB002848D" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.5:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "F46C1136-EEB4-472A-AC91-901987EABA1D" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.6:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "9B08C1A4-D8C0-42F4-B233-455E178135D5" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.7:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "E50876CA-C0A2-4EAA-8D7C-F539107C5450" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.9:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "281B8128-AEC8-4EE6-8990-F1B6DAFAABBB" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.10:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "629A80BC-4A13-492F-BF1D-9D37CB9D6CE5" }, { "criteria": "cpe:2.3:a:services_project:services:7.x-3.11:*:*:*:*:drupal:*:*", "vulnerable": true, "matchCriteriaId": "67475426-C059-41B2-B80E-42A03EBD8AAF" } ], "operator": "OR" } ] } ]