PT-2008-3763 · Drupal · Drupal Site Documentation Module

Publicado

2008-05-16

·

Atualizado

2021-04-19

·

CVE-2008-2271

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: The Site Documentation Drupal module versions 5.x before 5.x-1.8 The Site Documentation Drupal module versions 6.x before 6.x-1.1
Description: The issue allows remote authenticated users to gain privileges of other users. This is achieved by leveraging the access content permission to list tables and obtain session IDs from the database.
Recommendations: For versions 5.x before 5.x-1.8, update to version 5.x-1.8 or later. For versions 6.x before 6.x-1.1, update to version 6.x-1.1 or later.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2271

Produtos afetados

Drupal Site Documentation Module