Vulnerability Bulletins

SA-2008-026 - Drupal core - Access bypass

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-2008-026Project: Drupal coreVersion: 6.xDate: 2008-April-09Security risk: Moderately criticalExploitable from: RemoteVulnerability: Access bypassDescriptionThe menu system routes page requests to appropriate handlers. It also determines whether a user has access to pages based on several criteria, such as permissions assigned to a role. Drupal 6 features an entirely revised menu system, including changes to the way access is dealt with, which if not properly understood by

More info:

https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2008-04-09/sa-2008-026-drupal-core-access