Vulnerability Bulletins

SA-CORE-2012-004 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2012-004Project: Drupal coreVersion: 6.x, 7.xDate: 2012-December-19Security risk: Moderately criticalExploitable from: RemoteVulnerability: Access bypass, Arbitrary PHP code executionDescriptionMultiple vulnerabilities were fixed in the supported Drupal core versions 6 and 7.Access bypass (User module search - Drupal 6 and 7)A vulnerability was identified that allows blocked users to appear in user search results, even when the search results are viewed by

More info:

https://www.drupal.org/SA-CORE-2012-004