Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2012-1641
CVE information
Published
Last Modified
CVSSv2.0 Severity
Impact Analysis
Description
The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via admin/build/finder/import..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 6/10
- Exploit Score
- 6.8/10
- Access Vector
- Network
- Access Complexity
- Medium
- Authentication Required
- Single
- Impact Score
- 6.4/10
- Confidentiality Impact
- Partial
- Availability Impact
- Partial
- Integrity Impact
- Partial
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:danielb:finder:6.x-1.0:alpha22:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha9:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable4:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable1:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha10:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha16:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable2:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha5:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha2:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:rc3:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha21:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha1:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable7:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha12:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha8:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha24:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha27:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:beta2:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha4:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable0:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha14:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha17:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha26:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha19:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:rc2:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha23:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha28:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha13:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha11:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable6:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:rc1:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha6:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable3:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha3:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:beta3:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:beta1:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:unstable5:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha25:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:rc4:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha18:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha7:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha15:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.0:alpha20:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.1:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.2:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.3:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.4:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.5:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.6:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.7:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.8:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.9:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.10:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.11:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.12:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.13:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.14:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.15:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.16:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.17:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.18:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.19:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.20:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.21:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.23:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.24:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:6.x-1.x-dev:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.0:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.1:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.2:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.3:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.4:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.5:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.6:*:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-1.x:dev:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.0:alpha1:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.0:alpha6:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.0:alpha5:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.0:alpha3:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.0:alpha2:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.0:alpha4:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:danielb:finder:7.x-2.x:dev:*:*:*:*:*:* |
Yes
|
- | ||
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:* |
No
|
- |
References
- http://secunia.com/advisories/47915
- https://drupal.org/node/1432970
- http://www.osvdb.org/79014
- http://drupalcode.org/project/finder.git/commit/bc0cc82
- http://secunia.com/advisories/47943
- http://www.openwall.com/lists/oss-security/2012/04/07/1
- http://drupal.org/node/1432318
- http://www.openwall.com/lists/oss-security/2012/03/16/9
- http://drupal.org/node/1432320
- http://www.openwall.com/lists/oss-security/2012/03/19/9
- http://www.madirish.net/content/drupal-finder-6x-19-xss-and-remote-code-execution-vulner