CVE-2012-2922
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.0
Description
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| drupal | drupal | {"endIncluding":"7.14"} | |
| drupal | drupal | 5.0 | |
| drupal | drupal | 5.1 | |
| drupal | drupal | 5.2 | |
| drupal | drupal | 5.3 | |
| drupal | drupal | 5.4 | |
| drupal | drupal | 5.5 | |
| drupal | drupal | 5.6 | |
| drupal | drupal | 5.7 | |
| drupal | drupal | 5.8 | |
| drupal | drupal | 5.9 | |
| drupal | drupal | 5.10 | |
| drupal | drupal | 5.11 | |
| drupal | drupal | 5.12 | |
| drupal | drupal | 5.13 | |
| drupal | drupal | 5.14 | |
| drupal | drupal | 5.15 | |
| drupal | drupal | 5.16 | |
| drupal | drupal | 5.17 | |
| drupal | drupal | 5.18 | |
| drupal | drupal | 5.19 | |
| drupal | drupal | 5.20 | |
| drupal | drupal | 5.21 | |
| drupal | drupal | 5.22 | |
| drupal | drupal | 5.23 | |
| drupal | drupal | 6.0 | |
| drupal | drupal | 6.1 | |
| drupal | drupal | 6.2 | |
| drupal | drupal | 6.3 | |
| drupal | drupal | 6.4 | |
| drupal | drupal | 6.5 | |
| drupal | drupal | 6.6 | |
| drupal | drupal | 6.7 | |
| drupal | drupal | 6.8 | |
| drupal | drupal | 6.9 | |
| drupal | drupal | 6.10 | |
| drupal | drupal | 6.11 | |
| drupal | drupal | 6.12 | |
| drupal | drupal | 6.13 | |
| drupal | drupal | 6.14 | |
| drupal | drupal | 6.15 | |
| drupal | drupal | 6.16 | |
| drupal | drupal | 6.17 | |
| drupal | drupal | 6.18 | |
| drupal | drupal | 7.0 | |
| drupal | drupal | 7.1 | |
| drupal | drupal | 7.2 | |
| drupal | drupal | 7.3 | |
| drupal | drupal | 7.4 | |
| drupal | drupal | 7.5 | |
| drupal | drupal | 7.6 | |
| drupal | drupal | 7.7 | |
| drupal | drupal | 7.8 | |
| drupal | drupal | 7.9 | |
| drupal | drupal | 7.10 | |
| drupal | drupal | 7.11 | |
| drupal | drupal | 7.12 | |
References
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0052.html
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0053.html
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0055.html
- http://osvdb.org/81817
- http://secunia.com/advisories/49131
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:074
- http://www.openwall.com/lists/oss-security/2012/08/02/8
- http://www.securityfocus.com/bid/53454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75531
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0052.html
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0053.html
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0055.html
- http://osvdb.org/81817
- http://secunia.com/advisories/49131
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:074
- http://www.openwall.com/lists/oss-security/2012/08/02/8
- http://www.securityfocus.com/bid/53454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75531
CWEs
CWE-200
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.