The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.
References
Link | Resource |
---|---|
http://drupal.org/node/1859208 | Patch |
http://drupal.org/node/1859282 | Patch Vendor Advisory |
http://www.openwall.com/lists/oss-security/2012/12/20/1 | |
http://drupal.org/node/1859208 | Patch |
http://drupal.org/node/1859282 | Patch Vendor Advisory |
http://www.openwall.com/lists/oss-security/2012/12/20/1 |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://drupal.org/node/1859208 - Patch | |
References | () http://drupal.org/node/1859282 - Patch, Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2012/12/20/1 - |
Information
Published : 2013-01-03 01:55
Updated : 2024-11-21 01:45
NVD link : CVE-2012-5654
Mitre link : CVE-2012-5654
CVE.ORG link : CVE-2012-5654
JSON object : View
Products Affected
nodewords_project
- nodewords
drupal
- drupal
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor