PDA

View Full Version : Drupal Privilege System Administrative Access Vulnerability


admin
06-03-2005, 01:10 PM
Drupal
http://drupal.org
06-03-2005

Description:
A vulnerability has been reported in Drupal, which can be exploited by malicious people to bypass certain security restrictions.

The vulnerability is caused due to an input validation error in the privilege system and can be exploited to gain administrative privileges.

Successful exploitation requires that the "Public registrations" option has been enabled.

The vulnerability has been reported in versions 4.4.0, 4.4.1, 4.4.2, 4.5.0, 4.5.1, 4.5.2 and 4.6.0.

Solution:
Update to version 4.4.3, 4.5.3, or 4.6.1.
http://drupal.org/project