PT-2010-3938 · Drupal · Node Reference Module+2
Publicado
2010-06-21
·
Atualizado
2017-08-17
·
CVE-2010-2353
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Content Construction Kit (CCK) module versions 6.x before 6.x-2.7
Description
The issue concerns the Node Reference module in the CCK module for Drupal. It does not perform access checks for the source field in the backend URL for the autocomplete widget. This allows remote attackers to discover titles and IDs of controlled nodes.
Recommendations
For versions prior to 6.x-2.7, update to version 6.x-2.7 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Content Construction Kit (Cck) Module
Drupal
Node Reference Module