PT-2010-3938 · Drupal · Node Reference Module+2

Publicado

2010-06-21

·

Atualizado

2017-08-17

·

CVE-2010-2353

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Content Construction Kit (CCK) module versions 6.x before 6.x-2.7
Description The issue concerns the Node Reference module in the CCK module for Drupal. It does not perform access checks for the source field in the backend URL for the autocomplete widget. This allows remote attackers to discover titles and IDs of controlled nodes.
Recommendations For versions prior to 6.x-2.7, update to version 6.x-2.7 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2353

Produtos afetados

Content Construction Kit (Cck) Module
Drupal
Node Reference Module