Vulnerability Name: | CVE-2005-1871 (CCN-20891) | ||||||||
Assigned: | 2005-06-03 | ||||||||
Published: | 2005-06-03 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly." | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: FULLDISC Type: UNKNOWN 20050603 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue Source: MITRE Type: CNA CVE-2005-1871 Source: BUGTRAQ Type: UNKNOWN 20050603 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue Source: CCN Type: BugTraq Mailing List, 2005-06-03 10:47:42 [DRUPAL-SA-2005-001] New Drupal release fixes critical security issue Source: CCN Type: SA15372 Drupal Privilege System Administrative Access Vulnerability Source: SECUNIA Type: UNKNOWN 15372 Source: CCN Type: Drupal Web site drupal.org | community plumbing Source: OSVDB Type: UNKNOWN 17028 Source: CCN Type: OSVDB ID: 17028 Drupal Privilege Unspecified User Role Privilege Escalation Source: CCN Type: BID-13852 Drupal Unspecified Privilege Escalation Vulnerability Source: XF Type: UNKNOWN drupal-gain-privilege(20891) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |