CVE Vulnerabilities

CVE-2012-4495

Published: Oct 31, 2012 | Modified: Mar 02, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupals publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

Affected Software

Name Vendor Start Version End Version
Mimemail Mime_mail_module_project 6.x-1.0 (including) 6.x-1.0 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha1 (including) 6.x-1.0-alpha1 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha2 (including) 6.x-1.0-alpha2 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha3 (including) 6.x-1.0-alpha3 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha4 (including) 6.x-1.0-alpha4 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha5 (including) 6.x-1.0-alpha5 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha6 (including) 6.x-1.0-alpha6 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha7 (including) 6.x-1.0-alpha7 (including)
Mimemail Mime_mail_module_project 6.x-1.0-alpha8 (including) 6.x-1.0-alpha8 (including)
Mimemail Mime_mail_module_project 6.x-1.0-beta1 (including) 6.x-1.0-beta1 (including)
Mimemail Mime_mail_module_project 6.x-1.0-beta2 (including) 6.x-1.0-beta2 (including)
Mimemail Mime_mail_module_project 6.x-1.x-dev (including) 6.x-1.x-dev (including)

References