CVE-2012-5654

The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nodewords_project:nodewords:*:beta2:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:4.7-1.0:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:4.7-1.1:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:4.7-1.2:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:4.7-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.5:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.7:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.8:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.8:rc1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.9:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.10:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.11:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.12:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.13:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:5.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.3:alpha1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.3:alpha2:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.3:beta3:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.3:beta4:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.3:beta5:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.5:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.6:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.7:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.8:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.9:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.10:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.11:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta2:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta3:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta4:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta5:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta6:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta7:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta8:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:beta9:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.12:rc1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.13:*:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.13:rc1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.13:rc2:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.14:beta1:*:*:*:*:*:*
cpe:2.3:a:nodewords_project:nodewords:6.x-1.x:dev:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:45

Type Values Removed Values Added
References () http://drupal.org/node/1859208 - Patch () http://drupal.org/node/1859208 - Patch
References () http://drupal.org/node/1859282 - Patch, Vendor Advisory () http://drupal.org/node/1859282 - Patch, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2012/12/20/1 - () http://www.openwall.com/lists/oss-security/2012/12/20/1 -

Information

Published : 2013-01-03 01:55

Updated : 2024-11-21 01:45


NVD link : CVE-2012-5654

Mitre link : CVE-2012-5654

CVE.ORG link : CVE-2012-5654


JSON object : View

Products Affected

nodewords_project

  • nodewords

drupal

  • drupal
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor