VYPR
Unrated severityNVD Advisory· Published Jun 21, 2010· Updated Apr 29, 2026

CVE-2010-2353

CVE-2010-2353

Description

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

Affected products

22
  • Yves Chedemois/Cck22 versions
    cpe:2.3:a:yves_chedemois:cck:6.x-1.0-alpha:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:yves_chedemois:cck:6.x-1.0-alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-1.x-dev:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc10:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc4:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc5:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc6:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc7:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc8:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.0:rc9:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-2.x-dev:*:*:*:*:*:*:*
    • cpe:2.3:a:yves_chedemois:cck:6.x-3.x-dev:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.