Vulnerability Name: | CVE-2007-4436 (CCN-36105) | ||||||||
Assigned: | 2007-08-19 | ||||||||
Published: | 2007-08-19 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain project names via unspecified vectors; (3) obtain sensitive information via the statistics pages; and (4) read CVS project activity. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4436 Source: CCN Type: DRUPAL-SA-2007-020 Project and Project issue tracking - Access bypass Source: CONFIRM Type: Patch http://drupal.org/node/168760 Source: CCN Type: Project module for Drupal Web site Project | drupal.org Source: CCN Type: Project issue tracking module for Drupal Web site Project issue tracking | drupal.org Source: OSVDB Type: UNKNOWN 39632 Source: CCN Type: SA26510 Drupal Project and Project Issue Tracking Modules Insecure Permissions Source: SECUNIA Type: Patch, Vendor Advisory 26510 Source: CCN Type: OSVDB ID: 39632 Drupal Project / Project Issue Tracking Module Permission Weakness Information Disclosure Source: BID Type: UNKNOWN 25364 Source: CCN Type: BID-25364 Drupal Project and Project Issue Tracking Modules Insecure Permissions Security Bypass Vulnerability Source: XF Type: UNKNOWN project-title-information-disclosure(36105) Source: XF Type: UNKNOWN project-title-information-disclosure(36105) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |