CVE-2009-4558
Summary
| CVE | CVE-2009-4558 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-01-04 21:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body of an arbitrary node via unknown vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Drupal | All | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.0 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.1 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.2 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.3 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.4 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.5 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.6 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.7 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-1.x-dev | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-2.0-alpha1 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-2.0-alpha3 | All | All | All |
| Application | Unleashedmind | Img Assist | 5.x-2.x-dev | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-1.0 | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-1.0-beta1 | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-1.x-dev | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-2.0-alpha2 | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-2.0-alpha3 | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-2.x-dev | All | All | All |
| Application | Unleashedmind | Img Assist | 6.x-3.x-dev | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Drupal Image Assist Module Script Insertion and Information Disclosure - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Drupal Image Assist Module HTML Injection and Information Disclosure Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SA-CONTRIB-2009-043 - Image Assist - Multiple vulnerabilities | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch, Vendor Advisory |
| osvdb.org/55867 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.