CVE-2012-2302
Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive information via unspecified vectors.
Date published : 2012-07-25
http://drupal.org/node/1546224
http://drupalcode.org/project/sitedoc.git/commitdiff/521721c