« Volver al listado

CVE-2012-1649

Estado: ModificadaMedia (4.9)—

Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-1649",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-09-09T21:55:06.370",
  "references": [
    {
      "url": "http://drupal.org/node/1417186",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://drupal.org/node/1461438",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/48196",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.osvdb.org/79772",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/52232",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73608",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://drupal.org/node/1417186",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://drupal.org/node/1461438",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48196",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/79772",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/52232",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73608",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo Coll Aid antes de v6.x-1.9 para Drupal no impone restricciones de acceso, lo que permite a usuarios remotos autenticados con el permiso de administrar coolaid, modificar las páginas de su elección a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:39:58.710",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB560574-9327-406C-8DE1-AE20CFB6FF94",
              "versionEndIncluding": "6.x-1.8"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F07426C-4CA6-4CC7-ACA6-34104B08A114"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB6A592D-E0AE-4350-B48E-3D136E7A00C4"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB6584B5-1661-44F1-A681-8CA77A08F803"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86B0DD4B-7D24-43C1-8254-F55C2E556A6D"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30AE8F03-84AC-4D18-8E6F-66D07068ECB0"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7701353A-C6BF-4FD0-A125-78B6D63A12C8"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47B9CC5E-E085-440F-9BF5-F909423D1E02"
            },
            {
              "criteria": "cpe:2.3:a:danielb:cool_aid:6.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC7CFE3C-DB1E-404F-AD89-9156C796A22E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}