2.6
CVE-2012-1645
- EPSS 1.4%
- Veröffentlicht 28.08.2012 17:55:03
- Zuletzt bearbeitet 16.06.2026 23:39:57
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.4% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.openwall.com/lists/oss-security/2012/04/07/1
http://drupal.org/node/1441480
http://drupal.org/node/1441482
http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff
http://drupalcode.org/project/cdn.git/commitdiff/eca85e6
http://secunia.com/advisories/48032
http://www.osvdb.org/79317
https://drupal.org/node/1441502