The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the administer hotblocks permission to cause a denial of service (infinite loop and time out) via a block that references itself.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hotblocks | Justin_dodge | 6.x-1.5 (including) | 6.x-1.5 (including) |
Hotblocks | Justin_dodge | 6.x-1.6 (including) | 6.x-1.6 (including) |
Hotblocks | Justin_dodge | 6.x-1.7 (including) | 6.x-1.7 (including) |
Hotblocks | Justin_dodge | 6.x-1.x-dev (including) | 6.x-1.x-dev (including) |