Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-4558


The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body of an arbitrary node via unknown vectors.


Published

2010-01-04T21:30:00.467

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application unleashedmind img_assist 5.x-1.0 Yes
Application unleashedmind img_assist 5.x-1.1 Yes
Application unleashedmind img_assist 5.x-1.2 Yes
Application unleashedmind img_assist 5.x-1.3 Yes
Application unleashedmind img_assist 5.x-1.4 Yes
Application unleashedmind img_assist 5.x-1.5 Yes
Application unleashedmind img_assist 5.x-1.6 Yes
Application unleashedmind img_assist 5.x-1.7 Yes
Application unleashedmind img_assist 5.x-1.x-dev Yes
Application unleashedmind img_assist 5.x-2.0-alpha1 Yes
Application unleashedmind img_assist 5.x-2.0-alpha3 Yes
Application unleashedmind img_assist 5.x-2.x-dev Yes
Application unleashedmind img_assist 6.x-1.0 Yes
Application unleashedmind img_assist 6.x-1.0-beta1 Yes
Application unleashedmind img_assist 6.x-1.x-dev Yes
Application unleashedmind img_assist 6.x-2.0-alpha2 Yes
Application unleashedmind img_assist 6.x-2.0-alpha3 Yes
Application unleashedmind img_assist 6.x-2.x-dev Yes
Application unleashedmind img_assist 6.x-3.x-dev Yes
Application drupal drupal * No

References