« Volver al listado

CVE-2007-4436

Estado: ModificadaMedia (5)—

The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain project names via unspecified vectors; (3) obtain sensitive information via the statistics pages; and (4) read CVS project activity.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4436",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-20T22:17:00.000",
  "references": [
    {
      "url": "http://drupal.org/node/168760",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/39632",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26510",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/25364",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36105",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/168760",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/39632",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26510",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/25364",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36105",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain project names via unspecified vectors; (3) obtain sensitive information via the statistics pages; and (4) read CVS project activity."
    },
    {
      "lang": "es",
      "value": "El módulo Drupal Project versiones anteriores a 5.x-1.0, 4.7.x-2.3 y 4.7.x-1.3 y el módulo de seguimiento de problemas del Proyecto versiones anteriores a 5.x-1.0, versiones 4.7.x-2.4 y 4.7.x-1.4, no ejecutan apropiadamente los permisos, lo que permite a atacantes remotos (1) obtener información confidencial por medio del Módulo de Seguimiento y la página de publicaciones Recientes (Recent posts); (2) obtener los nombres de proyectos por medio de vectores no especificados; (3) obtener información confidencial por medio de las páginas de estadísticas; y (4) leer la actividad del proyecto CVS."
    }
  ],
  "lastModified": "2026-06-16T22:44:05.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:project:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04E313C5-E46E-4A14-B281-A5D56AE8DF6D",
              "versionEndIncluding": "4.7_1.1"
            },
            {
              "criteria": "cpe:2.3:a:drupal:project:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96B4F5ED-E3E5-45AE-A4A7-F3FA31D1A77D",
              "versionEndIncluding": "4.7_2.1"
            },
            {
              "criteria": "cpe:2.3:a:drupal:project:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2AA3D2D-AEE6-4C51-B052-9B2494CE0D7B",
              "versionEndIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:drupal:project_issue_tracking_module:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D04D5DB3-7F69-4A12-9E56-2C90F398F2B3",
              "versionEndIncluding": "4.7_1.1"
            },
            {
              "criteria": "cpe:2.3:a:drupal:project_issue_tracking_module:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "450CB0D0-B37D-4BE8-A338-B23BF0BCEB7E",
              "versionEndIncluding": "4.7_2.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}