Lucene search

K
cve[email protected]CVE-2012-5654
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-5654

2022-10-0316:15:30
CWE-200
web.nvd.nist.gov
18
cve-2012-5654
nodewords
d6 meta tags
drupal
information security
vulnerability
remote attackers
sensitive information

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.8%

The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.

Affected configurations

NVD
Node
nodewords_projectnodewordsRange6.x-1.14beta2
OR
nodewords_projectnodewordsMatch4.7-1.0
OR
nodewords_projectnodewordsMatch4.7-1.1
OR
nodewords_projectnodewordsMatch4.7-1.2
OR
nodewords_projectnodewordsMatch4.7-1.xdev
OR
nodewords_projectnodewordsMatch5.x-1.0
OR
nodewords_projectnodewordsMatch5.x-1.2
OR
nodewords_projectnodewordsMatch5.x-1.3
OR
nodewords_projectnodewordsMatch5.x-1.4
OR
nodewords_projectnodewordsMatch5.x-1.5
OR
nodewords_projectnodewordsMatch5.x-1.7
OR
nodewords_projectnodewordsMatch5.x-1.8
OR
nodewords_projectnodewordsMatch5.x-1.8rc1
OR
nodewords_projectnodewordsMatch5.x-1.9
OR
nodewords_projectnodewordsMatch5.x-1.10
OR
nodewords_projectnodewordsMatch5.x-1.11
OR
nodewords_projectnodewordsMatch5.x-1.12
OR
nodewords_projectnodewordsMatch5.x-1.13
OR
nodewords_projectnodewordsMatch5.x-1.xdev
OR
nodewords_projectnodewordsMatch6.x-1.0
OR
nodewords_projectnodewordsMatch6.x-1.0rc1
OR
nodewords_projectnodewordsMatch6.x-1.1
OR
nodewords_projectnodewordsMatch6.x-1.2
OR
nodewords_projectnodewordsMatch6.x-1.3
OR
nodewords_projectnodewordsMatch6.x-1.3alpha1
OR
nodewords_projectnodewordsMatch6.x-1.3alpha2
OR
nodewords_projectnodewordsMatch6.x-1.3beta3
OR
nodewords_projectnodewordsMatch6.x-1.3beta4
OR
nodewords_projectnodewordsMatch6.x-1.3beta5
OR
nodewords_projectnodewordsMatch6.x-1.4
OR
nodewords_projectnodewordsMatch6.x-1.5
OR
nodewords_projectnodewordsMatch6.x-1.6
OR
nodewords_projectnodewordsMatch6.x-1.7
OR
nodewords_projectnodewordsMatch6.x-1.8
OR
nodewords_projectnodewordsMatch6.x-1.9
OR
nodewords_projectnodewordsMatch6.x-1.10
OR
nodewords_projectnodewordsMatch6.x-1.11
OR
nodewords_projectnodewordsMatch6.x-1.12beta1
OR
nodewords_projectnodewordsMatch6.x-1.12beta2
OR
nodewords_projectnodewordsMatch6.x-1.12beta3
OR
nodewords_projectnodewordsMatch6.x-1.12beta4
OR
nodewords_projectnodewordsMatch6.x-1.12beta5
OR
nodewords_projectnodewordsMatch6.x-1.12beta6
OR
nodewords_projectnodewordsMatch6.x-1.12beta7
OR
nodewords_projectnodewordsMatch6.x-1.12beta8
OR
nodewords_projectnodewordsMatch6.x-1.12beta9
OR
nodewords_projectnodewordsMatch6.x-1.12rc1
OR
nodewords_projectnodewordsMatch6.x-1.13
OR
nodewords_projectnodewordsMatch6.x-1.13rc1
OR
nodewords_projectnodewordsMatch6.x-1.13rc2
OR
nodewords_projectnodewordsMatch6.x-1.14beta1
OR
nodewords_projectnodewordsMatch6.x-1.xdev
AND
drupaldrupalMatch-

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.4 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.8%

Related for CVE-2012-5654