CVE-2009-3568

Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
OR cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:5.x-2.0:*:*:*:*:*:*:*
cpe:2.3:a:dave_reid:commentrss:5.x-2.1:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:6.x-2.x:dev:*:*:*:*:*:*
cpe:2.3:a:dave_reid:commentrss:6.x-2.1:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:5.x-2.x:dev:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:6.x-2.0:*:*:*:*:*:*:*
cpe:2.3:a:gabor_hojtsy:commentrss:5.x-1.x:dev:*:*:*:*:*:*

Information

Published : 2009-10-06 13:30

Updated : 2009-10-07 21:00


NVD link : CVE-2009-3568

Mitre link : CVE-2009-3568


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

drupal

  • drupal

gabor_hojtsy

  • commentrss

dave_reid

  • commentrss