5
CVE-2011-1661
- EPSS 1.47%
- Veröffentlicht 10.04.2011 02:51:19
- Zuletzt bearbeitet 16.06.2026 23:29:46
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nicholas Thompson ≫ Node Quick Find Version6.x-1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.47% | 0.704 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://drupal.org/files/issues/db_rewrite_sql_12.patch
http://drupal.org/node/1080114
http://drupal.org/node/1118408
http://secunia.com/advisories/44046
http://www.securityfocus.com/bid/47238
https://exchange.xforce.ibmcloud.com/vulnerabilities/66604