Vulnerabilities > Angrydonuts

DATE CVE VULNERABILITY TITLE RISK
2009-06-16 CVE-2009-2077 Permissions, Privileges, and Access Controls vulnerability in Angrydonuts Views
Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in generated queries.
network
low complexity
angrydonuts drupal CWE-264
4.0
2009-06-16 CVE-2009-2075 Permissions, Privileges, and Access Controls vulnerability in Angrydonuts Nodequeue
Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, does not properly restrict access when displaying node titles, which has unknown impact and attack vectors.
network
low complexity
drupal angrydonuts CWE-264
7.5