Описание
The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:a:yves_chedemois:cck:6.x-1.0-alpha:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:beta:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc10:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc4:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc5:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc6:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc7:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc8:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc9:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.1:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.2:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.3:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.4:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.5:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.6:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-3.x-dev:*:*:*:*:*:*:*
EPSS
Процентиль: 69%
0.00616
Низкий
5 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
debian
около 15 лет назад
The Node Reference module in Content Construction Kit (CCK) module 6.x ...
github
около 3 лет назад
The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
EPSS
Процентиль: 69%
0.00616
Низкий
5 Medium
CVSS2
Дефекты
CWE-264