The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote attackers to view arbitrary images via a request that specifies an image's filename.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupal.org/node/554086 | patch vendor advisory |
http://drupal.org/node/554084 | patch vendor advisory |
http://drupal.org/node/505904 | patch exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52595 | vdb entry |
http://secunia.com/advisories/36412 | third party advisory vendor advisory |
http://drupal.org/node/554090 | patch vendor advisory |