The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.debian.org/security/2010/dsa-2113 | vendor advisory |
http://marc.info/?l=oss-security&m=128440896914512&w=2 | mailing list |
http://drupal.org/node/880476 | patch vendor advisory |
http://marc.info/?l=oss-security&m=128418560705305&w=2 | mailing list |
http://www.securityfocus.com/bid/42391 | vdb entry |