Vulnerability Bulletins

SA-2008-026 - Drupal core - Access bypass

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-2008-026Project: Drupal coreVersion: 6.xDate: 2008-April-09Security risk: Moderately criticalExploitable from: RemoteVulnerability: Access bypassDescriptionThe menu system routes page requests to appropriate handlers. It also determines whether a user has access to pages based on several criteria, such as permissions assigned to a role. Drupal 6 features an entirely revised menu system, including changes to the way access is dealt with, which if not properly understood by

More info:

https://www.drupal.org/node/244637