5
CVSSv2

CVE-2012-2922

Published: 21/05/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The request_path function in includes/bootstrap.inc in Drupal 7.14 and previous versions allows remote malicious users to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 7.9

drupal drupal 7.8

drupal drupal 7.1

drupal drupal 7.0

drupal drupal 6.6

drupal drupal 6.11

drupal drupal 6.7

drupal drupal 6.0

drupal drupal 6.4

drupal drupal 6.16

drupal drupal 5.15

drupal drupal 5.0

drupal drupal 5.18

drupal drupal 5.9

drupal drupal 5.5

drupal drupal 5.20

drupal drupal 5.10

drupal drupal

drupal drupal 7.12

drupal drupal 7.5

drupal drupal 7.4

drupal drupal 6.2

drupal drupal 6.3

drupal drupal 6.14

drupal drupal 5.23

drupal drupal 5.13

drupal drupal 5.2

drupal drupal 5.8

drupal drupal 5.4

drupal drupal 5.22

drupal drupal 5.19

drupal drupal 7.7

drupal drupal 7.6

drupal drupal 6.18

drupal drupal 6.8

drupal drupal 6.1

drupal drupal 6.5

drupal drupal 6.12

drupal drupal 6.15

drupal drupal 5.14

drupal drupal 5.16

drupal drupal 5.6

drupal drupal 5.3

drupal drupal 5.7

drupal drupal 7.11

drupal drupal 7.10

drupal drupal 7.3

drupal drupal 7.2

drupal drupal 6.10

drupal drupal 6.9

drupal drupal 6.13

drupal drupal 6.17

drupal drupal 5.12

drupal drupal 5.1

drupal drupal 5.17

drupal drupal 5.11

drupal drupal 5.21