// For flags

CVE-2012-1057

 

Severity Score

6.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site request forgery (CSRF) vulnerability in the clickthrough tracking functionality in the Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that increase node rankings via the tracking code, possibly related to improper "flood control."

Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en la funcionalidad 'clickthrough tracking' en el módulo Forward v6.x-1.x anterior a v6.x-1.21 y v7.x-1.x anterior a v7.x-1.3 para Drupal permite a atacantes remotos secuestras la autenticación para administradores para peticiones de incremento de la clasificación del nodo a través de un código de seguimiento, posiblemente relacionado con un control incorrecto.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-02-13 CVE Reserved
  • 2012-02-14 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.0"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.1
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.1"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.2
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.2"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.3
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.3"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.4
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.4"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.5
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.5"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.6
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.6"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.7
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.7"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.8
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.8"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.9
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.9"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.10
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.10"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.11
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.11"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.12
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.12"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.13
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.13"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.14
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.14"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.15
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.15"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.16
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.16"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.17
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.17"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.18
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.18"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.19
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.19"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.20
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.20"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
6.x-1.x-dev
Search vendor "Sean Robertson" for product "Forward" and version "6.x-1.x-dev"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
alpha1
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
alpha2
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
alpha3
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
rc1
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
rc2
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
rc3
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.0
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.0"
rc4
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.1
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.1"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.2
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.2"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe
Sean Robertson
Search vendor "Sean Robertson"
Forward
Search vendor "Sean Robertson" for product "Forward"
7.x-1.x-dev
Search vendor "Sean Robertson" for product "Forward" and version "7.x-1.x-dev"
-
Affected
in Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
*-
Safe