Vulnerabilities > CVE-2007-1368 - Unspecified vulnerability in Drupal Project Issue Tracking
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.
Vulnerable Configurations
References
- http://drupal.org/node/125832
- http://drupal.org/node/125832
- http://drupal.org/node/125833
- http://drupal.org/node/125833
- http://osvdb.org/33913
- http://osvdb.org/33913
- http://secunia.com/advisories/24409
- http://secunia.com/advisories/24409
- http://www.securityfocus.com/bid/22867
- http://www.securityfocus.com/bid/22867
- http://www.vupen.com/english/advisories/2007/0873
- http://www.vupen.com/english/advisories/2007/0873
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32871
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32871