Vulnerability Name: | CVE-2008-1729 (CCN-41755) | ||||||||
Assigned: | 2008-04-09 | ||||||||
Published: | 2008-04-09 | ||||||||
Updated: | 2021-04-19 | ||||||||
Summary: | The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types. | ||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-1729 Source: CCN Type: DRUPAL-SA-2008-026 Drupal core - Access bypass Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/244637 Source: CCN Type: SA29762 Drupal Menu System Security Bypass Vulnerabilities Source: SECUNIA Type: Third Party Advisory 29762 Source: OSVDB Type: Broken Link 44270 Source: CCN Type: OSVDB ID: 44270 Drupal Menu System Handler Security Bypass Source: BID Type: Patch, Third Party Advisory, VDB Entry 28714 Source: CCN Type: BID-28714 Drupal Menu System Security Bypass Vulnerabilities Source: VUPEN Type: Third Party Advisory ADV-2008-1185 Source: XF Type: Third Party Advisory, VDB Entry drupal-menusystem-security-bypass(41755) Source: XF Type: UNKNOWN drupal-menusystem-security-bypass(41755) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |