Vulnerability Name: | CVE-2010-3092 (CCN-61080) |
Assigned: | 2010-08-11 |
Published: | 2010-08-11 |
Updated: | 2010-09-22 |
Summary: | The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-264
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2010-3092
Source: CCN Type: SA-CORE-2010-002 Drupal core - Multiple vulnerabilities
Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/880476
Source: MLIST Type: UNKNOWN [oss-security] 20100911 CVE id requests: drupal
Source: MLIST Type: UNKNOWN [oss-security] 20100913 Re: CVE id requests: drupal
Source: CCN Type: SA40930 Drupal Multiple Vulnerabilities
Source: DEBIAN Type: UNKNOWN DSA-2113
Source: DEBIAN Type: DSA-2113 drupal6 -- several vulnerabilities
Source: CCN Type: OSVDB ID: 67072 Upload Module for Drupal Case Insensitivity Download Restriction Bypass
Source: BID Type: UNKNOWN 42391
Source: CCN Type: BID-42391 Drupal DRUPAL-SA-CORE-2010-002 Multiple Remote Vulnerabilities
Source: XF Type: UNKNOWN drupal-upload-filenames-security-bypass(61080)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:drupal:drupal:5.0:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.0:beta1:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.0:beta2:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.0:dev:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.0:rc1:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.0:rc2:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.1:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.2:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.3:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.4:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.5:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.6:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.7:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.8:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.9:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.10:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.11:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.12:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.13:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.14:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.15:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.16:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.17:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.18:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.19:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.20:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.21:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.22:*:*:*:*:*:*:* Configuration 2: cpe:/a:drupal:drupal:6.0:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:beta1:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:beta2:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:beta3:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:beta4:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:dev:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:rc1:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:rc2:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:rc3:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:rc4:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.1:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.2:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.3:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.4:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.5:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.6:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.7:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.8:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.9:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.10:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.11:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.12:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.13:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.14:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.15:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.16:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.17:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:drupal:drupal:5.6:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.0:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.0:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.1:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.1_rev1.1:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.2:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.3:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.4:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.5:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.7:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.2:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.8:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.1:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.9:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.3:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.4:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.10:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.5:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.11:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.12:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.6:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.9:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.7:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.13:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.15:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.14:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.10:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.16:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.11:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.17:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.12:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.18:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.13:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.14:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.20:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.16:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:5.21:*:*:*:*:*:*:*OR cpe:/a:drupal:drupal:6.15:*:*:*:*:*:*:*AND cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |