The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.
References
Link | Resource |
---|---|
http://drupal.org/node/1040728 | Patch |
http://drupal.org/node/1048998 | Patch Vendor Advisory |
http://osvdb.org/70767 | |
http://secunia.com/advisories/43185 | Vendor Advisory |
http://www.securityfocus.com/bid/46116 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65112 | |
http://drupal.org/node/1040728 | Patch |
http://drupal.org/node/1048998 | Patch Vendor Advisory |
http://osvdb.org/70767 | |
http://secunia.com/advisories/43185 | Vendor Advisory |
http://www.securityfocus.com/bid/46116 | Patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/65112 |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://drupal.org/node/1040728 - Patch | |
References | () http://drupal.org/node/1048998 - Patch, Vendor Advisory | |
References | () http://osvdb.org/70767 - | |
References | () http://secunia.com/advisories/43185 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/46116 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/65112 - |
Information
Published : 2011-02-07 21:00
Updated : 2024-11-21 01:25
NVD link : CVE-2011-0899
Mitre link : CVE-2011-0899
CVE.ORG link : CVE-2011-0899
JSON object : View
Products Affected
drupal
- drupal
johan_lindskog
- aes_encryption_module
CWE