Описание
The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:gordon_heydon:secure_pages:6.x-2.x:dev:-:*:-:drupal:*:*
EPSS
Процентиль: 55%
0.00331
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
github
больше 3 лет назад
The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page.
EPSS
Процентиль: 55%
0.00331
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-310