The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupalcode.org/project/uc_product_keys.git/commitdiff/19fa261 | patch exploit |
http://drupal.org/node/1585532 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75720 | vdb entry |
http://www.openwall.com/lists/oss-security/2012/06/14/3 | mailing list |
http://secunia.com/advisories/49169 | third party advisory |
http://osvdb.org/82005 | vdb entry |
http://drupal.org/node/1580752 | patch vendor advisory |