Vulnerability Name: | CCN-68880 | ||||||
Published: | 2011-07-27 | ||||||
Updated: | 2011-07-27 | ||||||
Summary: | Drupal core could allow a remote attacker to bypass security restrictions, caused by an error when the attach File upload fields to any entity type and ability to point individual File upload fields to the private file directory features are enabled. An attacker could exploit this vulnerability to download arbitrary files attached to restricted comments. | ||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||
CVSS v2 Severity: | 6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: Drupal Web Site Drupal - Open Source CMS | drupal.org Source: CCN Type: SA-CORE-2011-003 Drupal core - Access bypass Source: CCN Type: SA45394 Drupal Comment Attachment Security Bypass Vulnerability Source: CCN Type: BID-48911 Drupal Core File Download Security Bypass Vulnerability Source: XF Type: UNKNOWN drupalcore-comment-security-bypass(68880) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |