« Volver al listado

CVE-2008-3001

Estado: ModificadaAlta (9.3)—

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3001",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-03T18:41:00.000",
  "references": [
    {
      "url": "http://drupal.org/node/269479",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/30618",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/29677",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43011",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/269479",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/30618",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/29677",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43011",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions."
    },
    {
      "lang": "es",
      "value": "El módulo Aggregation 5.x versiones anteriores a 5.x-4.4 para Drupal permite a atacantes remotos subir ficheros con extensiones de su elección, y posiblemente ejecutar código de su elección, a través de una fuente RSS manipulada que permite subir ficheros con extensiones arbitrarias."
    }
  ],
  "lastModified": "2026-06-16T22:54:54.240",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CF7A917-F319-4C29-A843-99A36B4A83B5"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A64D861C-D011-4CE6-B7C6-EEB4D7CCDC81"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CA6032D-27F3-4D80-8714-7F3ACA2E8836"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D6F71C3-0DCB-418A-8FD4-072D49CF9945"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F16FEA3A-265F-4332-A1A1-2879CA5682CC"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C57C2C4F-F4EC-4A25-841D-8597EB1582B9"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E8D028E-51F2-4BE9-99F3-85D1BE440FA7"
            },
            {
              "criteria": "cpe:2.3:a:drupal:aggregation_module:5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35595D9F-0DBB-45BF-86A8-6548FFBB588D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorImpact": "Per Hyperlink Record 1026625, Drupal core is not affected. If you do not use the contributed Aggregation module, there is nothing you need to do.",
  "sourceIdentifier": "cve@mitre.org"
}