Access bypass in Drupal - CVE-2012-5652
Published: September 15, 2016 / Updated: September 15, 2016
Vulnerability identifier: #VU464
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5652
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to look the uploaded files over.
The weakness exists due to access control error and results in showing of uploaded files in RSS feeds and search results. The vulnerability increases possibility to view the information by users not allowed to read it before.
Successful exploitation of the weakness allows malicious users to obtain uploaded files.
The weakness exists due to access control error and results in showing of uploaded files in RSS feeds and search results. The vulnerability increases possibility to view the information by users not allowed to read it before.
Successful exploitation of the weakness allows malicious users to obtain uploaded files.
Affected software
Drupal
Fedora
drupal6
drupal7
Fedora
drupal6
drupal7
How to mitigate CVE-2012-5652
drupal6 - addressed in versions 6.27-1.el5, 6.27-1.el6
drupal7 - addressed in versions 7.18-1.el5, 7.18-1.el6
drupal7 - addressed in versions 7.18-1.el5, 7.18-1.el6