CVE-2013-4595
Beschrijving NL
De module Beveiligde pagina's 6.x-2.x vóór 6.x-2.0 voor Drupal komt niet goed overeen met URL's, waardoor HTTP wordt gebruikt in plaats van HTTPS en het voor aanvallers op afstand gemakkelijker wordt om gevoelige informatie te verkrijgen via een vervaardigde webpagina.
Origineel (Engels) tonen
The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page.