includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken links, which allows remote attackers to obtain sensitive information via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/48022 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2012/04/07/1 | mailing list |
http://drupalcode.org/project/linkchecker.git/commit/fef0ddf | patch |
https://drupal.org/node/1441252 | patch vendor advisory |
http://www.osvdb.org/79315 | vdb entry |
http://drupal.org/node/1440508 | patch |