The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupal.org/node/1547736 | patch |
http://www.openwall.com/lists/oss-security/2012/05/03/2 | mailing list |
http://www.osvdb.org/81556 | vdb entry |
http://drupalcode.org/project/spaces.git/commitdiff/cee919c | patch exploit |
http://www.securityfocus.com/bid/53252 | vdb entry |
http://drupal.org/node/1547730 | patch |
http://www.openwall.com/lists/oss-security/2012/05/03/1 | mailing list |
http://secunia.com/advisories/48930 | third party advisory vendor advisory |