Back to search
CVE-2011-2687
Published: Jul 27, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2011-8879
vendor-advisory
x_refsource_FEDORA
45081
third-party-advisory
x_refsource_SECUNIA
48505
vdb-entry
x_refsource_BID
FEDORA-2011-8878
vendor-advisory
x_refsource_FEDORA
http://drupal.org/node/1204582
x_refsource_CONFIRM
[oss-security] 20110712 Re: CVE Request -- Drupal 7 -- Access bypass in node listings (SA-CORE-2011-002)
mailing-list
x_refsource_MLIST
[oss-security] 20110711 CVE Request -- Drupal 7 -- Access bypass in node listings (SA-CORE-2011-002)
mailing-list
x_refsource_MLIST
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=633385
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=717874
x_refsource_CONFIRM
45291
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now