MEDIUM · 6.0

CVE-2007-0506

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain ...

Vulnerability Description

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
DrupalProject4.6
DrupalProject Issue Tracking Module4.7

References

FAQ

What is CVE-2007-0506?

CVE-2007-0506 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain ...

How severe is CVE-2007-0506?

CVE-2007-0506 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0506?

Check the references section above for vendor advisories and patch information. Affected products include: Drupal Project, Drupal Project Issue Tracking Module.