CVE-2012-1645
Estado: ModificadaBaja (2.6)—
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.40%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://drupal.org/node/1441480
- http://drupal.org/node/1441482
- http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff
- http://drupalcode.org/project/cdn.git/commitdiff/eca85e6
- http://secunia.com/advisories/48032
- http://www.openwall.com/lists/oss-security/2012/04/07/1
- http://www.osvdb.org/79317
- https://drupal.org/node/1441502
- http://drupal.org/node/1441480
- http://drupal.org/node/1441482
- http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff
- http://drupalcode.org/project/cdn.git/commitdiff/eca85e6
- http://secunia.com/advisories/48032
- http://www.openwall.com/lists/oss-security/2012/04/07/1
- http://www.osvdb.org/79317
- https://drupal.org/node/1441502
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-1645",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-08-28T17:55:03.577",
"references": [
{
"url": "http://drupal.org/node/1441480",
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1441482",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/eca85e6",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/48032",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
"source": "secalert@redhat.com"
},
{
"url": "http://www.osvdb.org/79317",
"source": "secalert@redhat.com"
},
{
"url": "https://drupal.org/node/1441502",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1441480",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/1441482",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/eca85e6",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48032",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/79317",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://drupal.org/node/1441502",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the \"Far Future expiration\" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php."
},
{
"lang": "es",
"value": "El módulo CDN v6.x-2.2 y v7.x-2.2 para Drupal, cuando está en ejecución en modo Origin Pull con la opción \"Far Future expiration\" habilitada, permite a atacantes remotos leer ficheros PHP de su elección a través de vectores no especificados, como se ha demostrado leyendo settings.php."
}
],
"lastModified": "2026-06-16T23:39:57.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wimleers:cdn:6.x-2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DE79600-89FA-4DA8-A85F-97202DB303A9"
},
{
"criteria": "cpe:2.3:a:wimleers:cdn:7.x-2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42D4A553-E06D-47C5-9B1F-5A509BB0370E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secalert@redhat.com"
}