« Back to list

CVE-2012-2302

Status: ModifiedMedium (5)—

Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-2302",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-07-25T21:55:01.837",
  "references": [
    {
      "url": "http://drupal.org/node/1546224",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://drupal.org/node/1547686",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://drupalcode.org/project/sitedoc.git/commitdiff/521721c",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/05/03/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/05/03/2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.osvdb.org/81555",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://drupal.org/node/1546224",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://drupal.org/node/1547686",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://drupalcode.org/project/sitedoc.git/commitdiff/521721c",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/05/03/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/05/03/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/81555",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "El módulo para Drupal Site Documentation (Sitedoc) no comprueba correctamente la ubicación de almacenamiento al comprimir, lo que permite a atacantes remotos obtener información sensible a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:41:19.077",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17B01156-3D0D-45D8-993D-964C56BD591D"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D166FFBD-63DA-4A62-86D1-ED98E273D53B"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8AA595F-ABED-4262-BC54-76F2570675FD"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C614FCEF-7AF3-4347-B388-899D4E8F4F3A"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8FB397B-6CC3-4507-BFEF-405370A782CE"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B3ABBF1-E05F-4926-B2F7-4C98CB71629A"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27F00739-F20F-46E5-A186-60A4A8AAD154"
            },
            {
              "criteria": "cpe:2.3:a:nancy_wichmann:sitedoc:6.x-1.x:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCDBA1B6-2B7A-4E2A-9D5F-D378C80C4534"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8B1170D-AD33-4C7A-892D-63AC71B032CF"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}