Vulnerability Name:

CVE-2008-0823 (CCN-40510)

Assigned:2008-02-13
Published:2008-02-13
Updated:2017-08-08
Summary:Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2008-0823

Source: CCN
Type: DRUPAL-SA-2008-017
Header image - Access bypass

Source: CONFIRM
Type: Patch
http://drupal.org/node/221359

Source: CCN
Type: Drupal Web site
Header image

Source: CCN
Type: SA28876
Drupal Header Image Module Security Bypass Vulnerability

Source: SECUNIA
Type: Vendor Advisory
28876

Source: CCN
Type: OSVDB ID: 41586
Header Image Module for Drupal Administration Pages Security Bypass

Source: BID
Type: Patch
27787

Source: CCN
Type: BID-27787
Drupal Header image Module Authentication Bypass Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2008-0571

Source: XF
Type: UNKNOWN
drupal-headerimage-security-bypass(40510)

Source: XF
Type: UNKNOWN
drupal-headerimage-security-bypass(40510)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:drupal:header_image:5.x-1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    drupal header image 5.x-1.0