The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-21T19:00:00

Updated: 2024-08-07T02:32:16.371Z

Reserved: 2010-06-21T00:00:00

Link: CVE-2010-2353

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-21T19:30:02.180

Modified: 2017-08-17T01:32:42.540

Link: CVE-2010-2353

cve-icon Redhat

No data.