5
CVSSv2

CVE-2010-2353

Published: 21/06/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Node Reference module in Content Construction Kit (CCK) module 6.x prior to 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote malicious users to discover titles and IDs of controlled nodes.

Vulnerable Product Search on Vulmon Subscribe to Product

yves_chedemois cck 6.x-2.6

yves_chedemois cck 6.x-2.5

yves_chedemois cck 6.x-2.0

yves_chedemois cck 6.x-2.1

yves_chedemois cck 6.x-2.3

yves_chedemois cck 6.x-2.2

yves_chedemois cck 6.x-1.x-dev

yves_chedemois cck 6.x-2.4

yves_chedemois cck 6.x-3.x-dev

yves_chedemois cck 6.x-2.x-dev

yves_chedemois cck 6.x-1.0-alpha