CVE-2010-2353
Summary
| CVE | CVE-2010-2353 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-21 19:30:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Drupal | All | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-1.0-alpha | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-1.x-dev | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | beta | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc1 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc10 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc2 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc3 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc4 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc5 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc6 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc7 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc8 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.0 | rc9 | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.1 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.2 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.3 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.4 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.5 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.6 | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-2.x-dev | All | All | All |
| Application | Yves Chedemois | Cck | 6.x-3.x-dev | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fedora update for drupal-cck - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 11 Update: drupal-cck-6.x.2.7-1.fc11 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| osvdb.org/65615 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SA-CONTRIB-2010-065 - Content Construction Kit (CCK) - Access Bypass | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch |
| [SECURITY] Fedora 12 Update: drupal-cck-6.x.2.7-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 13 Update: drupal-cck-6.x.2.7-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.