CVE-2012-2922: Infoleak
The requestpath function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2922?
CVE-2012-2922 has been classified as a moderate severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2012-2922?
To fix CVE-2012-2922, upgrade to Drupal version 7.15 or later.
What does CVE-2012-2922 affect?
CVE-2012-2922 affects Drupal versions 7.14 and earlier, as well as multiple versions in the 5.x and 6.x series.
What type of vulnerability is CVE-2012-2922?
CVE-2012-2922 is a security vulnerability that allows remote attackers to gain information about the installation path via the q[] parameter.
Can CVE-2012-2922 lead to further attacks?
Yes, by disclosing the installation path, CVE-2012-2922 can assist attackers in launching additional attacks on the vulnerable Drupal site.