CVE-2012-1645
Status: ModifiedLow (2.6)—
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.
CVSS
- Version: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N
- Base score: 2.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.40%
- Percentile among all scored CVEs: 72
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-200
References
- http://drupal.org/node/1441480
- http://drupal.org/node/1441482
- http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff
- http://drupalcode.org/project/cdn.git/commitdiff/eca85e6
- http://secunia.com/advisories/48032
- http://www.openwall.com/lists/oss-security/2012/04/07/1
- http://www.osvdb.org/79317
- https://drupal.org/node/1441502
- http://drupal.org/node/1441480
- http://drupal.org/node/1441482
- http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff
- http://drupalcode.org/project/cdn.git/commitdiff/eca85e6
- http://secunia.com/advisories/48032
- http://www.openwall.com/lists/oss-security/2012/04/07/1
- http://www.osvdb.org/79317
- https://drupal.org/node/1441502
Raw JSON (NVD)
Show
{
"id": "CVE-2012-1645",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-08-28T17:55:03.577",
"references": [
{
"url": "http://drupal.org/node/1441480",
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1441482",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/eca85e6",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/48032",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
"source": "secalert@redhat.com"
},
{
"url": "http://www.osvdb.org/79317",
"source": "secalert@redhat.com"
},
{
"url": "https://drupal.org/node/1441502",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://drupal.org/node/1441480",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/1441482",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupalcode.org/project/cdn.git/commitdiff/eca85e6",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48032",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/04/07/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/79317",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://drupal.org/node/1441502",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the \"Far Future expiration\" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php."
},
{
"lang": "es",
"value": "El módulo CDN v6.x-2.2 y v7.x-2.2 para Drupal, cuando está en ejecución en modo Origin Pull con la opción \"Far Future expiration\" habilitada, permite a atacantes remotos leer ficheros PHP de su elección a través de vectores no especificados, como se ha demostrado leyendo settings.php."
}
],
"lastModified": "2026-06-16T23:39:57.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wimleers:cdn:6.x-2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DE79600-89FA-4DA8-A85F-97202DB303A9"
},
{
"criteria": "cpe:2.3:a:wimleers:cdn:7.x-2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42D4A553-E06D-47C5-9B1F-5A509BB0370E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secalert@redhat.com"
}