Vulnerabilities > CVE-2011-0899 - Unspecified vulnerability in Johan Lindskog AES Encryption Module 7.X1.4

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.

Vulnerable Configurations

Part Description Count
Application
Johan_Lindskog
1
Application
Drupal
1

D2sec

nameDrupal AES encryption File Disclosure
urlhttp://www.d2sec.com/exploits/drupal_aes_encryption_file_disclosure.html