PT-2005-4712 · Php+1 · Php+1

Published

2005-12-03

·

Updated

2018-10-19

·

CVE-2005-3974

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions 4.5.0 through 4.5.5 Drupal versions 4.6.0 through 4.6.3
Description The issue allows remote attackers to bypass the "access user profiles" permission due to incorrect enforcement of user privileges when running on PHP5.
Recommendations For versions 4.5.0 through 4.5.5, update to a version that correctly enforces user privileges. For versions 4.6.0 through 4.6.3, update to a version that correctly enforces user privileges. As a temporary workaround, consider restricting access to user profiles until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3974
DSA-958-1

Affected Products

Drupal
Php