The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://drupal.org/node/152806 - Patch | |
References | () http://drupal.org/node/158022 - Patch | |
References | () http://drupal.org/node/158025 - Patch | |
References | () http://osvdb.org/37896 - | |
References | () http://secunia.com/advisories/25999 - | |
References | () http://www.securityfocus.com/bid/24862 - | |
References | () http://www.vupen.com/english/advisories/2007/2469 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/35318 - |
Information
Published : 2007-07-11 17:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3690
Mitre link : CVE-2007-3690
CVE.ORG link : CVE-2007-3690
JSON object : View
Products Affected
drupal
- forward_module
CWE