The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Node_parameter_control | Chris_desautels | 6.x-1.0 (including) | 6.x-1.0 (including) |