Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in generated queries.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupal.org/node/488082 | patch vendor advisory |
http://www.securityfocus.com/bid/35304 | vdb entry patch |
http://secunia.com/advisories/35425 | third party advisory vendor advisory |
http://drupal.org/node/488068 | patch vendor advisory |