CVE-2010-2353
Published Jun 21, 2010
Last updated 7 years ago
Overview
- Description
- The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-1.0-alpha:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CE8ED07-644D-4B7A-9D25-31846C73B16C" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-1.x-dev:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "894AAB4C-0687-49FF-80D2-07733232C86E" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9981BCE7-4563-4B81-94D7-E15CC7A949C0" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DE0DF1B-BD55-4BE0-82E5-D6C8F4DB0ED2" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7212E3AC-0707-4C73-BCB8-ECB387621371" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc10:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CBF8E73-7EBC-400E-8045-C89A2400C346" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F091E8C8-ECB2-4CC9-A692-DFD50FAFE0D3" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C2D28B8-26B4-4965-95A5-F2CE0CE6C897" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B76DBD4-1AAB-4B2D-AC67-606CD9FD6209" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B25EE03-5D36-499A-BA45-C5FDD09144DE" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3A7B8CE-4D89-40E3-8717-9CA43CA227DD" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E6A0133-B19E-4C9F-ACD3-DBC327722B28" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc8:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2675E82-5546-405A-B1E8-2B656E49A903" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc9:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7AF2DABF-D278-4AC4-B1A1-4CA5E6782695" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64EA01B6-78C1-4244-8E9E-3E38F99A9C58" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A8FFBDF-CC67-409C-9AA4-965998EE1D5F" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "325695A4-AC8F-42E3-A817-C39D002DBCB9" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54D00828-64FD-4068-8CD7-04D2BCE5AC84" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13EDA2FA-C962-4F58-BA3D-9F8FFF801D9C" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F8EA159-92F4-4CEA-A117-0BFD07179357" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-2.x-dev:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "578E1219-B38F-4166-923D-FC48E8558707" }, { "criteria": "cpe:2.3:a:yves_chedemois:cck:6.x-3.x-dev:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8FC11CA-4FEB-4593-A43F-5711E5611D6D" } ], "operator": "OR" } ], "operator": "AND" } ]