|
|
| |
| The Node Embed module for Drupal is prone to a security-bypass vulnerability. |
| |
Credit:
The information has been provided by Paul Aumer-Ryan.
The original article can be found at: http://www.securityfocus.com/bid/53835
|
| |
Vulnerable Systems:
* Drupal Node Embed 7.x-1.x
* Drupal Node Embed 6.X-1.4
Immune Systems:
* Drupal Node Embed 7.x-1.0
* Drupal Node Embed 6.X-1.5
An attacker can exploit this issue to bypass certain security restrictions and view node titles; this may aid in launching further attacks.
Vendor Status:
Drupal had issued an update for this vulnerability
Patch Availability:
http://drupal.org/node/1619824
Disclosure Timeline:
Initial Release: Jun 06 2012
|
|
blog comments powered by
|