CVE Vulnerabilities

CVE-2012-1649

Published: Sep 09, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Cool_aid Danielb * 6.x-1.8 (including)
Cool_aid Danielb 6.x-1.0 (including) 6.x-1.0 (including)
Cool_aid Danielb 6.x-1.1 (including) 6.x-1.1 (including)
Cool_aid Danielb 6.x-1.2 (including) 6.x-1.2 (including)
Cool_aid Danielb 6.x-1.3 (including) 6.x-1.3 (including)
Cool_aid Danielb 6.x-1.4 (including) 6.x-1.4 (including)
Cool_aid Danielb 6.x-1.6 (including) 6.x-1.6 (including)
Cool_aid Danielb 6.x-1.7 (including) 6.x-1.7 (including)
Cool_aid Danielb 6.x-1.x-dev (including) 6.x-1.x-dev (including)

References