First published: Tue May 13 2014(Updated: )
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Monster Menus | =7.x-1.0 | |
Drupal Monster Menus | =7.x-1.1 | |
Drupal Monster Menus | =7.x-1.2 | |
Drupal Monster Menus | =7.x-1.3 | |
Drupal Monster Menus | =7.x-1.4 | |
Drupal Monster Menus | =7.x-1.5 | |
Drupal Monster Menus | =7.x-1.6 | |
Drupal Monster Menus | =7.x-1.7 | |
Drupal Monster Menus | =7.x-1.8 | |
Drupal Monster Menus | =7.x-1.9 | |
Drupal Monster Menus | =7.x-1.10 | |
Drupal Monster Menus | =7.x-1.11 | |
Drupal Monster Menus | =7.x-1.12 | |
Drupal Monster Menus | =7.x-1.13 | |
Drupal Monster Menus | =7.x-1.14 | |
Drupal Monster Menus | =7.x-1.x-dev | |
Drupal | ||
All of | ||
Any of | ||
Drupal Monster Menus | =7.x-1.0 | |
Drupal Monster Menus | =7.x-1.1 | |
Drupal Monster Menus | =7.x-1.2 | |
Drupal Monster Menus | =7.x-1.3 | |
Drupal Monster Menus | =7.x-1.4 | |
Drupal Monster Menus | =7.x-1.5 | |
Drupal Monster Menus | =7.x-1.6 | |
Drupal Monster Menus | =7.x-1.7 | |
Drupal Monster Menus | =7.x-1.8 | |
Drupal Monster Menus | =7.x-1.9 | |
Drupal Monster Menus | =7.x-1.10 | |
Drupal Monster Menus | =7.x-1.11 | |
Drupal Monster Menus | =7.x-1.12 | |
Drupal Monster Menus | =7.x-1.13 | |
Drupal Monster Menus | =7.x-1.14 | |
Drupal Monster Menus | =7.x-1.x-dev | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4504 has been classified as a moderate severity vulnerability due to its ability to expose arbitrary node comments to remote attackers.
To fix CVE-2013-4504, update the Monster Menus module to version 7.x-1.15 or later.
CVE-2013-4504 affects all versions of the Monster Menus module prior to 7.x-1.15.
CVE-2013-4504 allows remote attackers to read arbitrary node comments through a crafted URL.
Disabling the Monster Menus module is a temporary workaround until it can be updated to a secure version.