CVE-2012-1056
N/A
N/A
Summary
The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://secunia.com/advisories/47851
- http://drupal.org/node/1425150
- http://www.securityfocus.com/bid/51826
- http://drupal.org/node/1423722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72920
- http://osvdb.org/78817
References
- http://secunia.com/advisories/47851
- http://drupal.org/node/1425150
- http://www.securityfocus.com/bid/51826
- http://drupal.org/node/1423722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72920
- http://osvdb.org/78817
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.