PT-2005-4712 · Php+1 · Php+1
Publicado
2005-12-03
·
Atualizado
2018-10-19
·
CVE-2005-3974
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 4.5.0 through 4.5.5
Drupal versions 4.6.0 through 4.6.3
Description
The issue allows remote attackers to bypass the "access user profiles" permission due to incorrect enforcement of user privileges when running on PHP5.
Recommendations
For versions 4.5.0 through 4.5.5, update to a version that correctly enforces user privileges.
For versions 4.6.0 through 4.6.3, update to a version that correctly enforces user privileges.
As a temporary workaround, consider restricting access to user profiles until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal
Php