When an anonymous user fails to login due to mistyping his username or password, and the page he is on contains a sortable table, the (incorrect) username and password were included in links on the table. If the user visits these links the password may then be leaked to external sites via the HTTP referer.
In addition, if the anonymous user is enticed to visit the site via a specially crafted URL while the Drupal page cache is enabled, a malicious user could be able to retrieve the (incorrect) username and password from the page cache.
Part of security release SA-CORE-2009-007
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8
- Drupal 6.9
- Drupal 6.10
- Drupal 6.11
- Drupal 6.12