CVE-2011-1661
10.04.2011, 02:51
The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.Enginsight
Vendor | Product | Version |
---|---|---|
nicholas_thompson | node_quick_find | 6.x-1.1:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References