Vulnerabilities > CVE-2013-2198 - Incorrect Authorization vulnerability in Login Security Project Login Security
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://www.openwall.com/lists/oss-security/2013/06/20/3
- http://www.openwall.com/lists/oss-security/2013/06/20/3
- https://drupal.org/node/2023503
- https://drupal.org/node/2023503
- https://drupal.org/node/2023507
- https://drupal.org/node/2023507
- https://drupal.org/node/2023585
- https://drupal.org/node/2023585