6.8
CVSSv2

CVE-2009-3207

Published: 16/09/2009 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ImageCache module 5.x prior to 5.x-2.5 and 6.x prior to 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote malicious users to view arbitrary images via a request that specifies an image's filename.

Vulnerable Product Search on Vulmon Subscribe to Product

drewish imagecache 5.x-2.1

drewish imagecache 5.x-1.7

drewish imagecache 6.x-2.0

drewish imagecache 5.x-2.x

drewish imagecache 5.x-1.1

drewish imagecache 5.x-2.3

drewish imagecache 5.x-2.2

drewish imagecache 5.x-2.0

drewish imagecache 5.x-1.5

drewish imagecache 5.x-1.6

drewish imagecache 6.x-1.0

drewish imagecache 5.x-1.x

drewish imagecache 5.x-1.0

drewish imagecache 5.x-1.2

drewish imagecache 5.x-1.3

drewish imagecache 5.x-2.4

drewish imagecache 6.x-2.x-dev

drewish imagecache 5.x-1.4