Back to search
CVE-2012-2922
Published: May 21, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
81817
vdb-entry
x_refsource_OSVDB
drupal-index-path-disclosure(75531)
vdb-entry
x_refsource_XF
20120510 Drupal 7.14 <= Full Path Disclosure Vulnerability (Update)
mailing-list
x_refsource_BUGTRAQ
MDVSA-2013:074
vendor-advisory
x_refsource_MANDRIVA
49131
third-party-advisory
x_refsource_SECUNIA
53454
vdb-entry
x_refsource_BID
20120510 Drupal 7.14 <= Full Path Disclosure Vulnerability
mailing-list
x_refsource_BUGTRAQ
20120510 Re: Drupal 7.14 <= Full Path Disclosure Vulnerability
mailing-list
x_refsource_BUGTRAQ
[oss-security] 20120802 Re: CVE Request for Drupal contributed modules
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now