The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.
References
Link | Resource |
---|---|
http://drupal.org/node/1859282 | Patch Vendor Advisory |
http://www.openwall.com/lists/oss-security/2012/12/20/1 | |
http://drupal.org/node/1859208 | Patch |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2013-01-02 17:55
Updated : 2013-01-02 21:00
NVD link : CVE-2012-5654
Mitre link : CVE-2012-5654
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
nodewords_project
- nodewords
drupal
- drupal