CVE-2008-1729
Last modified
CVE-2008-1729 is a vulnerability of currently unknown severity. The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.. EPSS estimates a 2.40% chance of exploitation in the next 30 days.
Description
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | >= 6.0, < 6.2 |
References
- http://drupal.org/node/244637Patch, Vendor Advisory
- http://secunia.com/advisories/29762Third Party Advisory
- http://www.osvdb.org/44270Broken Link
- http://www.securityfocus.com/bid/28714Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1185/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41755Third Party Advisory, VDB Entry
- http://drupal.org/node/244637Patch, Vendor Advisory
- http://secunia.com/advisories/29762Third Party Advisory
- http://www.osvdb.org/44270Broken Link
- http://www.securityfocus.com/bid/28714Patch, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1185/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41755Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-1729?
How severe is CVE-2008-1729?
How do I fix CVE-2008-1729?
Are you affected by CVE-2008-1729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
