5
CVSSv2

CVE-2009-4515

Published: 31/12/2009 Updated: 08/01/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Storm module 6.x prior to 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote malicious users to read node titles via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

speedtech storm 6.x-1.x

speedtech storm 6.x-1.5

speedtech storm 6.x-1.23

speedtech storm 6.x-1.24

speedtech storm 6.x-1.16

speedtech storm 6.x-1.18

speedtech storm 6.x-1.10

speedtech storm 6.x-1.1

speedtech storm 6.x-1.0

speedtech storm 6.x-1.9

speedtech storm 6.x-1.8

speedtech storm 6.x-1.12

speedtech storm 6.x-1.13

speedtech storm 6.x-1.14

speedtech storm 6.x-1.15

speedtech storm 6.x-1.7

speedtech storm 6.x-1.6

speedtech storm 6.x-1.20

speedtech storm 6.x-1.21

speedtech storm 6.x-1.11

speedtech storm 6.x-1.3

speedtech storm 6.x-1.4

speedtech storm 6.x-1.22

speedtech storm 6.x-1.2

speedtech storm 6.x-1.17

speedtech storm 6.x-1.19