« Volver al listado

CVE-2012-5007

Estado: ModificadaMedia (5)—

The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspecified vectors related to the fillpdf_merge_pdf function and incorrect arguments, a different vulnerability than CVE-2012-1625. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-5007",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-09-20T03:46:36.490",
  "references": [
    {
      "url": "http://drupal.org/node/1394428",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/78181",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/47418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/51288",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/1394428",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/78181",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/47418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/51288",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspecified vectors related to the fillpdf_merge_pdf function and incorrect arguments, a different vulnerability than CVE-2012-1625.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "El módulo Fill PDF v7.x-1.x antes de v7.x-1.2 para Drupal permite a atacantes remotos escribir en archivos PDF de su elección a través de vectores no especificados relacionados con la función fillpdf_merge_pdf y unos argumentos incorrectos. Se trata de una vulnerabilidad diferente a CVE-2012-1625a NOTA: algunos de estos detalles han sido obtenidos a partir de información de terceros.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:46:03.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wizonesolutions:fillpdf:7.x-1.:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C4BD2EA-B651-433C-AFA1-B73A18280483"
            },
            {
              "criteria": "cpe:2.3:a:wizonesolutions:fillpdf:7.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10FE3EFE-AF19-4B49-A8B8-DD76CC55583C"
            },
            {
              "criteria": "cpe:2.3:a:wizonesolutions:fillpdf:7.x-1.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A6D079E-4E21-43BC-A579-937ED6CAC003"
            },
            {
              "criteria": "cpe:2.3:a:wizonesolutions:fillpdf:7.x-1.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48E7B5DC-5423-49C2-BA23-C24637F4E7E0"
            },
            {
              "criteria": "cpe:2.3:a:wizonesolutions:fillpdf:7.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D4C712B-B5FD-4629-8511-005EE6DA2FCA"
            },
            {
              "criteria": "cpe:2.3:a:wizonesolutions:fillpdf:7.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5DA989C-B003-4311-99C0-E7A5A5A63A49"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}