CVE Vulnerabilities

CVE-2005-3974

Published: Dec 03, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the access user profiles permission.

Affected Software

NameVendorStart VersionEnd Version
DrupalDrupal4.5 (including)4.5 (including)
DrupalDrupal4.5.1 (including)4.5.1 (including)
DrupalDrupal4.5.2 (including)4.5.2 (including)
DrupalDrupal4.5.3 (including)4.5.3 (including)
DrupalDrupal4.5.4 (including)4.5.4 (including)
DrupalDrupal4.5.5 (including)4.5.5 (including)
DrupalDrupal4.6 (including)4.6 (including)
DrupalDrupal4.6.1 (including)4.6.1 (including)
DrupalDrupal4.6.2 (including)4.6.2 (including)
DrupalDrupal4.6.3 (including)4.6.3 (including)

References