PT-2005-2828 · Drupal · Drupal
Uwe Hermann
·
Published
2005-06-07
·
Updated
2016-10-18
·
CVE-2005-1871
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Drupal versions 4.4.0 through 4.6.0
Description
The issue is related to an unknown vulnerability in the privilege system. When public registration is enabled, remote attackers can gain privileges due to an input check that is not implemented properly.
Recommendations
For versions 4.4.0 through 4.6.0, consider disabling public registration as a temporary workaround until a patch is available. Restrict access to the privilege system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal