CVE-2005-3974
N/A
N/A
Summary
Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.vupen.com/english/advisories/2005/2684
- http://drupal.org/files/sa-2005-009/4.6.3.patch
- http://www.debian.org/security/2006/dsa-958
- http://www.securityfocus.com/bid/15674
- http://secunia.com/advisories/18630
- http://www.securityfocus.com/archive/1/418336/100/0/threaded
- http://drupal.org/files/sa-2005-009/advisory.txt
- http://secunia.com/advisories/17824
References
- http://www.vupen.com/english/advisories/2005/2684
- http://drupal.org/files/sa-2005-009/4.6.3.patch
- http://www.debian.org/security/2006/dsa-958
- http://www.securityfocus.com/bid/15674
- http://secunia.com/advisories/18630
- http://www.securityfocus.com/archive/1/418336/100/0/threaded
- http://drupal.org/files/sa-2005-009/advisory.txt
- http://secunia.com/advisories/17824
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.