Description
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
Remediation
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-45038)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2009-1891)
MediaWiki CVE-2023-36674 Vulnerability (CVE-2023-36674)
WordPress Plugin Sexy Add Template Cross-Site Request Forgery (1.0)