CVE Vulnerabilities

CVE-2008-6908

Published: Aug 06, 2009 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.

Affected Software

Name Vendor Start Version End Version
Services Marc_ingram 5.x-0.9 (including) 5.x-0.9 (including)
Services Marc_ingram 5.x-0.91 (including) 5.x-0.91 (including)
Services Marc_ingram 5.x-1.x-dev (including) 5.x-1.x-dev (including)
Services Marc_ingram 6.x-0.9 (including) 6.x-0.9 (including)
Services Marc_ingram 6.x-0.11 (including) 6.x-0.11 (including)
Services Marc_ingram 6.x-0.12 (including) 6.x-0.12 (including)
Services Marc_ingram 6.x-1.x-dev (including) 6.x-1.x-dev (including)

References