CVE-2012-2721
CVE-2012-2721
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://drupalcode.org/project/og.git/commitdiff/1485708http://drupal.org/node/1619736http://drupal.org/node/1619810http://secunia.com/advisories/49397https://exchange.xforce.ibmcloud.com/vulnerabilities/76150http://www.openwall.com/lists/oss-security/2012/06/14/3http://www.osvdb.org/82728http://www.securityfocus.com/bid/53838