The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Forward | Sean_robertson | 6.x-1.0 (including) | 6.x-1.0 (including) |
Forward | Sean_robertson | 6.x-1.1 (including) | 6.x-1.1 (including) |
Forward | Sean_robertson | 6.x-1.2 (including) | 6.x-1.2 (including) |
Forward | Sean_robertson | 6.x-1.3 (including) | 6.x-1.3 (including) |
Forward | Sean_robertson | 6.x-1.4 (including) | 6.x-1.4 (including) |
Forward | Sean_robertson | 6.x-1.5 (including) | 6.x-1.5 (including) |
Forward | Sean_robertson | 6.x-1.6 (including) | 6.x-1.6 (including) |
Forward | Sean_robertson | 6.x-1.7 (including) | 6.x-1.7 (including) |
Forward | Sean_robertson | 6.x-1.8 (including) | 6.x-1.8 (including) |
Forward | Sean_robertson | 6.x-1.9 (including) | 6.x-1.9 (including) |
Forward | Sean_robertson | 6.x-1.10 (including) | 6.x-1.10 (including) |
Forward | Sean_robertson | 6.x-1.11 (including) | 6.x-1.11 (including) |
Forward | Sean_robertson | 6.x-1.12 (including) | 6.x-1.12 (including) |
Forward | Sean_robertson | 6.x-1.13 (including) | 6.x-1.13 (including) |
Forward | Sean_robertson | 6.x-1.14 (including) | 6.x-1.14 (including) |
Forward | Sean_robertson | 6.x-1.15 (including) | 6.x-1.15 (including) |
Forward | Sean_robertson | 6.x-1.16 (including) | 6.x-1.16 (including) |
Forward | Sean_robertson | 6.x-1.17 (including) | 6.x-1.17 (including) |
Forward | Sean_robertson | 6.x-1.18 (including) | 6.x-1.18 (including) |
Forward | Sean_robertson | 6.x-1.19 (including) | 6.x-1.19 (including) |
Forward | Sean_robertson | 6.x-1.20 (including) | 6.x-1.20 (including) |
Forward | Sean_robertson | 6.x-1.x-dev (including) | 6.x-1.x-dev (including) |