Vulnerability Name:

CVE-2006-1227 (CCN-25197)

Assigned:2006-03-13
Published:2006-03-13
Updated:2018-10-18
Summary:Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2006-1227

Source: CCN
Type: Drupal Advisory ID: DRUPAL-SA-2006-001
Security bypass in menu.module

Source: CONFIRM
Type: Patch, Vendor Advisory
http://drupal.org/node/53796

Source: CCN
Type: Drupal Web site
Drupal

Source: CCN
Type: SA19245
Drupal Multiple Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
19245

Source: SECUNIA
Type: Patch, Vendor Advisory
19257

Source: SREASON
Type: UNKNOWN
578

Source: DEBIAN
Type: Patch, Vendor Advisory
DSA-1007

Source: DEBIAN
Type: DSA-1007
drupal -- several vulnerabilities

Source: OSVDB
Type: Patch
23909

Source: CCN
Type: OSVDB ID: 23909
Drupal menu.module Menu Item Creation Page Restriction Bypass

Source: BUGTRAQ
Type: UNKNOWN
20060314 [DRUPAL-SA-2006-001] Drupal 4.6.6 / 4.5.8 fixes access control issue

Source: BID
Type: UNKNOWN
17104

Source: CCN
Type: BID-17104
Drupal Multiple Input Validation Vulnerabilities

Source: XF
Type: UNKNOWN
drupal-menumodule-bypass-security(25197)

Source: XF
Type: UNKNOWN
drupal-menumodule-bypass-security(25197)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:drupal:drupal:4.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:drupal:drupal:4.6.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:1007
    V
    several vulnerabilities
    2006-03-17
    BACK
    drupal drupal 4.5.0
    drupal drupal 4.5.1
    drupal drupal 4.5.2
    drupal drupal 4.5.3
    drupal drupal 4.5.4
    drupal drupal 4.5.5
    drupal drupal 4.5.6
    drupal drupal 4.5.7
    drupal drupal 4.6.0
    drupal drupal 4.6.1
    drupal drupal 4.6.2
    drupal drupal 4.6.3
    drupal drupal 4.6.4
    drupal drupal 4.6.5