TROYANOSYVIRUS
Back to CVEs

CVE-2012-2922

N/A

Description

The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.

CVE Details

CVSS v3.1 ScoreN/A
Published5/21/2012
Last Modified4/29/2026
Sourcenvd
Honeypot Sightings0

Affected Products

drupal:drupal

Weaknesses (CWE)

CWE-200

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.