4.3
CVE-2012-5654
- EPSS 0.28%
- Veröffentlicht 03.01.2013 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nodewords Project ≫ Nodewords Updatebeta2 Version <= 6.x-1.14
Nodewords Project ≫ Nodewords Version4.7-1.0
Nodewords Project ≫ Nodewords Version4.7-1.1
Nodewords Project ≫ Nodewords Version4.7-1.2
Nodewords Project ≫ Nodewords Version4.7-1.x Updatedev
Nodewords Project ≫ Nodewords Version5.x-1.0
Nodewords Project ≫ Nodewords Version5.x-1.2
Nodewords Project ≫ Nodewords Version5.x-1.3
Nodewords Project ≫ Nodewords Version5.x-1.4
Nodewords Project ≫ Nodewords Version5.x-1.5
Nodewords Project ≫ Nodewords Version5.x-1.7
Nodewords Project ≫ Nodewords Version5.x-1.8
Nodewords Project ≫ Nodewords Version5.x-1.8 Updaterc1
Nodewords Project ≫ Nodewords Version5.x-1.9
Nodewords Project ≫ Nodewords Version5.x-1.10
Nodewords Project ≫ Nodewords Version5.x-1.11
Nodewords Project ≫ Nodewords Version5.x-1.12
Nodewords Project ≫ Nodewords Version5.x-1.13
Nodewords Project ≫ Nodewords Version5.x-1.x Updatedev
Nodewords Project ≫ Nodewords Version6.x-1.0
Nodewords Project ≫ Nodewords Version6.x-1.0 Updaterc1
Nodewords Project ≫ Nodewords Version6.x-1.1
Nodewords Project ≫ Nodewords Version6.x-1.2
Nodewords Project ≫ Nodewords Version6.x-1.3
Nodewords Project ≫ Nodewords Version6.x-1.3 Updatealpha1
Nodewords Project ≫ Nodewords Version6.x-1.3 Updatealpha2
Nodewords Project ≫ Nodewords Version6.x-1.3 Updatebeta3
Nodewords Project ≫ Nodewords Version6.x-1.3 Updatebeta4
Nodewords Project ≫ Nodewords Version6.x-1.3 Updatebeta5
Nodewords Project ≫ Nodewords Version6.x-1.4
Nodewords Project ≫ Nodewords Version6.x-1.5
Nodewords Project ≫ Nodewords Version6.x-1.6
Nodewords Project ≫ Nodewords Version6.x-1.7
Nodewords Project ≫ Nodewords Version6.x-1.8
Nodewords Project ≫ Nodewords Version6.x-1.9
Nodewords Project ≫ Nodewords Version6.x-1.10
Nodewords Project ≫ Nodewords Version6.x-1.11
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta1
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta2
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta3
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta4
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta5
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta6
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta7
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta8
Nodewords Project ≫ Nodewords Version6.x-1.12 Updatebeta9
Nodewords Project ≫ Nodewords Version6.x-1.12 Updaterc1
Nodewords Project ≫ Nodewords Version6.x-1.13
Nodewords Project ≫ Nodewords Version6.x-1.13 Updaterc1
Nodewords Project ≫ Nodewords Version6.x-1.13 Updaterc2
Nodewords Project ≫ Nodewords Version6.x-1.14 Updatebeta1
Nodewords Project ≫ Nodewords Version6.x-1.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.487 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.