5

CVE-2010-2353

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yves Chedemois ≫ Cck Version 6.x-1.0-alpha
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-1.x-dev
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update beta
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc1
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc10
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc2
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc3
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc4
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc5
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc6
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc7
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc8
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.0 Update rc9
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.1
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.2
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.3
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.4
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.5
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.6
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-2.x-dev
   Drupal ≫ Drupal
Yves Chedemois ≫ Cck Version 6.x-3.x-dev
   Drupal ≫ Drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.77% 0.752
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://drupal.org/node/829566
Patch
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043100.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043172.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043191.html
http://osvdb.org/65615
http://secunia.com/advisories/40243
Vendor Advisory
http://secunia.com/advisories/40318
http://www.vupen.com/english/advisories/2010/1546
https://exchange.xforce.ibmcloud.com/vulnerabilities/59515