« Volver al listado

CVE-2008-6908

Estado: ModificadaAlta (7.5)—

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-6908",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-06T17:30:00.407",
  "references": [
    {
      "url": "http://drupal.org/node/348295",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/50743",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/32894",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47458",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/348295",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/50743",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/32894",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47458",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges."
    },
    {
      "lang": "es",
      "value": "Services v5.x anterior a v5.x-0.92 y v6.x anterior a v6.x-0.13, un módulo de Drupal, utiliza un hash inseguro al firmar las solicitudes, lo que permite a atacantes remotos suplantar a otros usuarios y obtener privilegios."
    }
  ],
  "lastModified": "2026-06-16T23:03:12.833",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:5.x-0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "971DC8A9-7356-4D6F-993C-5F5F28EF037D"
            },
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:5.x-0.91:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E589A651-CBBB-49E5-8D67-68DBE6159570"
            },
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:5.x-1.x-dev:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCF5BAF1-3FF5-4D36-8B18-0C1DA07C4344"
            },
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:6.x-0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B403152-7E41-43D5-A71D-1FFBCD99C334"
            },
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:6.x-0.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47E13993-D2EE-40AD-98E2-EC5B76589970"
            },
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:6.x-0.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBF94F5E-8314-436F-8259-0190E32586A3"
            },
            {
              "criteria": "cpe:2.3:a:marc_ingram:services:6.x-1.x-dev:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4307E56C-E735-416C-B170-225609059BEE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}