Vulnerability Bulletins |
SA-CORE-2011-003 - Drupal core - Access bypass |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2011-003Project: Drupal coreVersion: 7.xDate: 2011-July-27Security risk: Less criticalExploitable from: RemoteVulnerability: Access bypassDescriptionCVE: CVE-2011-2726Access bypass in private file fields on comments. Drupal 7 contains two new features: the ability to attach File upload fields to any entity type in the system and the ability to point individual File upload fields to the private file directory.If a Drupal site is using these features on comments, and More info: https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2011-07-27/sa-core-2011-003-drupal-core-access |
|






