Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*", "matchCriteriaId": "522EC26C-B265-4A61-8751-0866EA735DCE", "versionEndIncluding": "6.4", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:*:*:*:*:*:*:*", "matchCriteriaId": "FFE07AAD-9207-4C5F-A108-7F7753E4F48C", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "D4149703-F7BB-4513-9379-992C089532D1", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:beta2:*:*:*:*:*:*", "matchCriteriaId": "FCBC7BB8-2B50-476D-BD96-C968F105CE10", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:beta3:*:*:*:*:*:*", "matchCriteriaId": "550778E2-BEE5-403D-8744-0B18C5D3AFF3", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:beta4:*:*:*:*:*:*", "matchCriteriaId": "31B9F954-3A10-4378-A842-4061E97056DE", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-1:*:*:*:*:*:*", "matchCriteriaId": "7954FAA5-0455-407F-B16F-CB1FD24F9FB5", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-2:*:*:*:*:*:*", "matchCriteriaId": "B254CD4E-51A2-4E8D-9B59-FA5610F76683", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-3:*:*:*:*:*:*", "matchCriteriaId": "A4DF0926-E487-4F3B-B85B-2690127FE1FA", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.0:rc-4:*:*:*:*:*:*", "matchCriteriaId": "D05C77D9-E816-41A6-80DB-F4815980A83C", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.1:*:*:*:*:*:*:*", "matchCriteriaId": "52D8F291-CBEB-4EAA-9388-F63066A2DFA0", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.2:*:*:*:*:*:*:*", "matchCriteriaId": "B0BD5AEC-F20E-4E53-AF3F-2C60BA2D2171", "vulnerable": true}, {"criteria": "cpe:2.3:a:drupal:drupal:6.3:*:*:*:*:*:*:*", "matchCriteriaId": "A5D76BC5-0409-4D78-8064-A78B923E9167", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and \"attach files to content,\" related to a \"logic error.\""}, {"lang": "es", "value": "La funcionalidad de validaci\u00f3n del n\u00facleo del m\u00f3dulo de subida en Drupal 6.x anterior a 6.5 permite a un usuario remoto autentificado sobrepasar las restricciones de acceso y \"a\u00f1adir archivos al contenido\"; est\u00e1 relacionado con un \"error l\u00f3gico\"."}], "id": "CVE-2008-4789", "lastModified": "2025-04-09T00:30:58.490", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "SINGLE", "availabilityImpact": "PARTIAL", "baseScore": 6.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 6.8, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": true, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2008-10-29T15:31:35.493", "references": [{"source": "cve@mitre.org", "tags": ["Patch", "Vendor Advisory"], "url": "http://drupal.org/node/318706"}, {"source": "cve@mitre.org", "url": "http://secunia.com/advisories/32198"}, {"source": "cve@mitre.org", "url": "http://www.openwall.com/lists/oss-security/2008/10/21/7"}, {"source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45755"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Patch", "Vendor Advisory"], "url": "http://drupal.org/node/318706"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://secunia.com/advisories/32198"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.openwall.com/lists/oss-security/2008/10/21/7"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45755"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-264"}], "source": "nvd@nist.gov", "type": "Primary"}]}