CVE-2010-2353

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
OR cpe:2.3:a:yves_chedemois:cck:6.x-1.0-alpha:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:beta:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc10:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc4:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc5:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc6:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc7:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc8:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc9:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.1:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.2:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.3:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.4:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.5:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.6:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-2.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:yves_chedemois:cck:6.x-3.x-dev:*:*:*:*:*:*:*

History

21 Nov 2024, 01:16

Type Values Removed Values Added
References () http://drupal.org/node/829566 - Patch () http://drupal.org/node/829566 - Patch
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043100.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043100.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043172.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043172.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043191.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043191.html -
References () http://osvdb.org/65615 - () http://osvdb.org/65615 -
References () http://secunia.com/advisories/40243 - Vendor Advisory () http://secunia.com/advisories/40243 - Vendor Advisory
References () http://secunia.com/advisories/40318 - () http://secunia.com/advisories/40318 -
References () http://www.vupen.com/english/advisories/2010/1546 - () http://www.vupen.com/english/advisories/2010/1546 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/59515 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/59515 -

Information

Published : 2010-06-21 19:30

Updated : 2024-11-21 01:16


NVD link : CVE-2010-2353

Mitre link : CVE-2010-2353

CVE.ORG link : CVE-2010-2353


JSON object : View

Products Affected

drupal

  • drupal

yves_chedemois

  • cck
CWE
CWE-264

Permissions, Privileges, and Access Controls