PT-2005-4712 · Php+1 · Php+1

Publicado

2005-12-03

·

Atualizado

2018-10-19

·

CVE-2005-3974

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions 4.5.0 through 4.5.5 Drupal versions 4.6.0 through 4.6.3
Description The issue allows remote attackers to bypass the "access user profiles" permission due to incorrect enforcement of user privileges when running on PHP5.
Recommendations For versions 4.5.0 through 4.5.5, update to a version that correctly enforces user privileges. For versions 4.6.0 through 4.6.3, update to a version that correctly enforces user privileges. As a temporary workaround, consider restricting access to user profiles until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3974
DSA-958-1

Produtos afetados

Drupal
Php