5

CVE-2010-2353

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

Data is provided by the National Vulnerability Database (NVD)
Yves ChedemoisCck Version6.x-1.0-alpha
   DrupalDrupal
Yves ChedemoisCck Version6.x-1.x-dev
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updatebeta
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc1
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc10
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc2
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc3
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc4
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc5
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc6
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc7
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc8
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.0 Updaterc9
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.1
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.2
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.3
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.4
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.5
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.6
   DrupalDrupal
Yves ChedemoisCck Version6.x-2.x-dev
   DrupalDrupal
Yves ChedemoisCck Version6.x-3.x-dev
   DrupalDrupal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.68% 0.709
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N