Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://drupalcode.org/project/drupal.git/commitdiff/da8023a | patch |
http://www.mandriva.com/security/advisories?name=MDVSA-2013:074 | vendor advisory |
http://drupal.org/SA-CORE-2012-004 | patch vendor advisory |
http://www.securityfocus.com/bid/56993 | vdb entry |
http://drupalcode.org/project/drupal.git/commitdiff/b47f95d | patch |
http://www.osvdb.org/88528 | vdb entry |
http://www.debian.org/security/2013/dsa-2776 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/80792 | vdb entry |
http://www.openwall.com/lists/oss-security/2012/12/20/1 | mailing list |