Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.811705
Categoría:Web application abuses
Título:Drupal Core Multiple Vulnerabilities (SA-CORE-2017-004) - Linux
Resumen:Drupal is prone to multiple vulnerabilities.
Descripción:Summary:
Drupal is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- An error in the 'views' subsystem/module which did not restrict access to
the Ajax endpoint to only views configured to use Ajax.

- An error when using the REST API, users without the correct permission can
post comments via REST that are approved even if the user does not have
permission to post approved comments.

- An error in the entity access system that could allow unwanted access to
view, create, update, or delete entities.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to bypass certain security restrictions.

Affected Software/OS:
Drupal core version 8.x versions prior to
8.3.7 on Linux.

Solution:
Upgrade to Drupal core version 8.3.7 or
later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-6923
BugTraq ID: 100368
http://www.securityfocus.com/bid/100368
http://www.securitytracker.com/id/1039200
Common Vulnerability Exposure (CVE) ID: CVE-2017-6924
Common Vulnerability Exposure (CVE) ID: CVE-2017-6925
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.