The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Explorer sessions to "switch users" when uploading a file, which has unspecified impact possibly involving file uploads to the wrong user directory, aka "Session Management Vulnerability."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/06/14/3 | mailing list |
http://www.osvdb.org/82575 | vdb entry |
http://drupal.org/node/1608864 | patch vendor advisory |
http://drupal.org/node/1598782 | patch |
http://secunia.com/advisories/49316 | third party advisory vendor advisory |