5
CVE-2012-2302
- EPSS 0.52%
- Published 25.07.2012 21:55:01
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive information via unspecified vectors.
Data is provided by the National Vulnerability Database (NVD)
Nancy Wichmann ≫ Sitedoc Version6.x-1.0
Nancy Wichmann ≫ Sitedoc Version6.x-1.0 Updatebeta1
Nancy Wichmann ≫ Sitedoc Version6.x-1.0 Updatebeta2
Nancy Wichmann ≫ Sitedoc Version6.x-1.0 Updaterc4
Nancy Wichmann ≫ Sitedoc Version6.x-1.1
Nancy Wichmann ≫ Sitedoc Version6.x-1.2
Nancy Wichmann ≫ Sitedoc Version6.x-1.3
Nancy Wichmann ≫ Sitedoc Version6.x-1.x Updatedev
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.52% | 0.639 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.