5
CVSSv2

CVE-2011-1661

Published: 10/04/2011 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote malicious users to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.

Vulnerable Product Search on Vulmon Subscribe to Product

nicholas_thompson node_quick_find 6.x-1.1