CVE-2008-1729
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the…
Does this matter?
Lower severity and a low EPSS score (2.40%). Track it; it rarely justifies an emergency change on its own.
Description
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 2.40% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- drupal/drupal
- Source
- cve@mitre.org
References
- http://drupal.org/node/244637Patch, Vendor Advisory
- http://secunia.com/advisories/29762Third Party Advisory
- http://www.osvdb.org/44270Broken Link
- http://www.securityfocus.com/bid/28714Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1185/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41755Third Party Advisory, VDB Entry
- http://drupal.org/node/244637Patch, Vendor Advisory
- http://secunia.com/advisories/29762Third Party Advisory
- http://www.osvdb.org/44270Broken Link
- http://www.securityfocus.com/bid/28714Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1185/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41755Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.