The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/36165 | vdb entry |
http://www.osvdb.org/57435 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52818 | vdb entry |
http://secunia.com/advisories/36497 | third party advisory vendor advisory |
http://drupal.org/node/560298 | vendor advisory |
http://www.vupen.com/english/advisories/2009/2452 | vdb entry vendor advisory |