MEDIUM · 5.0

CVE-2008-2771

The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass rest...

Vulnerability Description

The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass restrictions and modify the node hierarchy via unspecified attack vectors.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
DrupalDrupal5.0
DrupalNode Hierarchy Module5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-2771?

CVE-2008-2771 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass rest...

How severe is CVE-2008-2771?

CVE-2008-2771 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-2771?

Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal, Drupal Node Hierarchy Module.