The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access restrictions and read comments by using the autocomplete path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Commentreference | Kristof_de_jaeger | * | 5.x-1.1 (including) |
Commentreference | Kristof_de_jaeger | * | 6.x-1.2 (including) |
Commentreference | Kristof_de_jaeger | 5.x-1.0 (including) | 5.x-1.0 (including) |
Commentreference | Kristof_de_jaeger | 5.x-1.x-dev (including) | 5.x-1.x-dev (including) |
Commentreference | Kristof_de_jaeger | 6.x-1.0 (including) | 6.x-1.0 (including) |
Commentreference | Kristof_de_jaeger | 6.x-1.1 (including) | 6.x-1.1 (including) |
Commentreference | Kristof_de_jaeger | 6.x-1.x-dev (including) | 6.x-1.x-dev (including) |