Vulnerability Bulletins |
SA-CORE-2011-003 - Drupal core - Access bypass |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2011-003Project: Drupal coreVersion: 7.xDate: 2011-July-27Security risk: Less criticalExploitable from: RemoteVulnerability: Access bypassDescriptionCVE: CVE-2011-2726Access bypass in private file fields on comments. Drupal 7 contains two new features: the ability to attach File upload fields to any entity type in the system and the ability to point individual File upload fields to the private file directory.If a Drupal site is using these features on comments, and More info: https://www.drupal.org/node/1231510 |
|






