The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which allows remote attackers to obtain sensitive site configuration information that is specified by the $conf variable in settings.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Advertisement | John_franklin | 6.x-2.0 (including) | 6.x-2.0 (including) |
Advertisement | John_franklin | 6.x-2.0-alpha1 (including) | 6.x-2.0-alpha1 (including) |
Advertisement | John_franklin | 6.x-2.0-alpha2 (including) | 6.x-2.0-alpha2 (including) |
Advertisement | John_franklin | 6.x-2.0-beta1 (including) | 6.x-2.0-beta1 (including) |
Advertisement | John_franklin | 6.x-2.0-beta2 (including) | 6.x-2.0-beta2 (including) |
Advertisement | John_franklin | 6.x-2.0-beta3 (including) | 6.x-2.0-beta3 (including) |
Advertisement | John_franklin | 6.x-2.0-beta4 (including) | 6.x-2.0-beta4 (including) |
Advertisement | John_franklin | 6.x-2.0-beta5 (including) | 6.x-2.0-beta5 (including) |
Advertisement | John_franklin | 6.x-2.0-beta6 (including) | 6.x-2.0-beta6 (including) |
Advertisement | John_franklin | 6.x-2.0-rc1 (including) | 6.x-2.0-rc1 (including) |
Advertisement | John_franklin | 6.x-2.1 (including) | 6.x-2.1 (including) |
Advertisement | John_franklin | 6.x-2.1-rc1 (including) | 6.x-2.1-rc1 (including) |
Advertisement | John_franklin | 6.x-2.2 (including) | 6.x-2.2 (including) |
Advertisement | John_franklin | 6.x-2.2-rc1 (including) | 6.x-2.2-rc1 (including) |
Advertisement | John_franklin | 6.x-2.3-beta1 (including) | 6.x-2.3-beta1 (including) |
Advertisement | John_franklin | 6.x-2.3-dev (including) | 6.x-2.3-dev (including) |
Advertisement | John_franklin | 6.x-2.x (including) | 6.x-2.x (including) |
Advertisement | John_franklin | 6.x-2.x-dev (including) | 6.x-2.x-dev (including) |