Launchpad.net

CVE 2012-5652

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

See the CVE page on Mitre.org for more details.