2.1 CVE-2012-2299
Exploit Patch
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database.
https://nvd.nist.gov/vuln/detail/CVE-2012-2299
Categories
CWE-255
References
BID
CONFIRM Patch Exploit
MISC Patch
http://drupal.org/node/1547674 Patch Vendor Advisory |
SECUNIA
48935 Vendor Advisory |
_MLIST
CPE
cpe | start | end |
---|---|---|
Configuration 1 | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:beta1:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:beta2:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:beta3:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:beta4:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:beta5:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:beta6:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:dev:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc2:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc3:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc4:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc5:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc6:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.0:rc7:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:6.x-2.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:alpha1:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:alpha2:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:alpha3:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:beta1:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:beta2:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:beta3:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:beta4:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:dev:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:rc2:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:rc3:*:*:*:*:*:* | ||
cpe:2.3:a:ubercart:ubercart:7.x-3.0:rc4:*:*:*:*:*:* | ||
Running on/with | ||
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:* |
REMEDIATION
Patch
EXPLOITS
Exploit-db.com
id | description | date | |
---|---|---|---|
No known exploits |
Other (github, ...)
Url |
---|
http://drupalcode.org/project/ubercart.git/commitdiff/035d2cb |
http://drupalcode.org/project/ubercart.git/commitdiff/8c61e84 |
CAPEC
Common Attack Pattern Enumerations and Classifications
id | description | severity |
---|---|---|
No entry |
MITRE
Sherlock® flash
Take a picture of your computer network in a few clicks !
The Sherlock® flash audit solution allows you to perform an audit to strengthen the security of your IT assets. Vulnerability analysis of your physical and virtual equipment. Patch planning by priority level and time available. Detailed and intuitive reporting.
