The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass restrictions and modify the node hierarchy via unspecified attack vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/30622 | third party advisory patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43006 | vdb entry |
http://drupal.org/node/269473 | patch |
http://www.securityfocus.com/bid/29675 | vdb entry patch |