The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T02:32:16.371Z
Reserved: 2010-06-21T00:00:00
Link: CVE-2010-2353

No data.

Status : Deferred
Published: 2010-06-21T19:30:02.180
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-2353

No data.