The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node privileges in certain circumstances involving subqueue creation, which allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/37288 | third party advisory vendor advisory |
http://drupal.org/node/623554 | patch vendor advisory |
http://drupal.org/node/617496 | patch vendor advisory |
http://drupal.org/node/617500 | patch vendor advisory |
http://www.securityfocus.com/bid/36925 | vdb entry patch |
http://osvdb.org/59675 | vdb entry |