« Volver al listado

CVE-2008-3745

Estado: ModificadaMedia (5.5)—

The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3745",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-08-27T15:21:00.000",
  "references": [
    {
      "url": "http://drupal.org/node/295053",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31825",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30689",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2392",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=459108",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44458",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00259.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00508.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/295053",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31825",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30689",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2392",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=459108",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44458",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00259.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00508.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo Upload en Drupal 6.x anterior a 6.4, permite a usuarios autenticados en remoto editar nodos, eliminar ficheros y descargar adjuntos no autorizados a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T22:56:27.557",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FFE07AAD-9207-4C5F-A108-7F7753E4F48C"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52D8F291-CBEB-4EAA-9388-F63066A2DFA0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0BD5AEC-F20E-4E53-AF3F-2C60BA2D2171"
            },
            {
              "criteria": "cpe:2.3:a:drupal:drupal:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5D76BC5-0409-4D78-8064-A78B923E9167"
            },
            {
              "criteria": "cpe:2.3:a:drupal:upload_module:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE3063A2-814A-4C23-A1D4-89E70B5BF9DE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}