CVE-2012-1056

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:sean_robertson:forward:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.5:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.6:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.7:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.8:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.9:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.10:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.11:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.12:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.13:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.14:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.15:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.16:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.17:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.18:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.19:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.20:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:6.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:sean_robertson:forward:7.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.0:rc4:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:sean_robertson:forward:7.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-02-14 00:55

Updated : 2024-02-28 11:41


NVD link : CVE-2012-1056

Mitre link : CVE-2012-1056

CVE.ORG link : CVE-2012-1056


JSON object : View

Products Affected

drupal

  • drupal

sean_robertson

  • forward
CWE
CWE-264

Permissions, Privileges, and Access Controls