The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholders for a default value, which allows remote attackers to read session variables via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/36708 | vdb entry |
http://secunia.com/advisories/37021 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2009/2923 | vdb entry vendor advisory |
http://drupal.org/node/604920 | patch |
http://drupal.org/node/604942 | patch vendor advisory |
http://drupal.org/node/604922 | patch |
http://osvdb.org/58946 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53797 | vdb entry |