PT-2005-4712 · Php+1 · Php+1
Published
2005-12-03
·
Updated
2018-10-19
·
CVE-2005-3974
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 4.5.0 through 4.5.5
Drupal versions 4.6.0 through 4.6.3
Description
The issue allows remote attackers to bypass the "access user profiles" permission due to incorrect enforcement of user privileges when running on PHP5.
Recommendations
For versions 4.5.0 through 4.5.5, update to a version that correctly enforces user privileges.
For versions 4.6.0 through 4.6.3, update to a version that correctly enforces user privileges.
As a temporary workaround, consider restricting access to user profiles until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal
Php