Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | |||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.811705 |
Categoría: | Web application abuses |
Título: | Drupal Core Multiple Vulnerabilities (SA-CORE-2017-004) - Linux |
Resumen: | Drupal is prone to multiple vulnerabilities. |
Descripción: | Summary: Drupal is prone to multiple vulnerabilities. Vulnerability Insight: Multiple flaws are due to: - An error in the 'views' subsystem/module which did not restrict access to the Ajax endpoint to only views configured to use Ajax. - An error when using the REST API, users without the correct permission can post comments via REST that are approved even if the user does not have permission to post approved comments. - An error in the entity access system that could allow unwanted access to view, create, update, or delete entities. Vulnerability Impact: Successful exploitation will allow remote attackers to bypass certain security restrictions. Affected Software/OS: Drupal core version 8.x versions prior to 8.3.7 on Linux. Solution: Upgrade to Drupal core version 8.3.7 or later. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-6923 BugTraq ID: 100368 http://www.securityfocus.com/bid/100368 http://www.securitytracker.com/id/1039200 Common Vulnerability Exposure (CVE) ID: CVE-2017-6924 Common Vulnerability Exposure (CVE) ID: CVE-2017-6925 |
Copyright | Copyright (C) 2017 Greenbone Networks GmbH |
Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |