CVE-2005-3974: Medium severity drupal drupal vulnerability
Published Dec 3, 2005
·Updated
Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.
Affected Software
10 affected components
Drupal Drupal=4.6
Drupal Drupal=4.5.4
Drupal Drupal=4.5.2
Drupal Drupal=4.6.2
Drupal Drupal=4.5.1
Drupal Drupal=4.6.3
Drupal Drupal=4.5.5
Drupal Drupal=4.5
Drupal Drupal=4.6.1
Drupal Drupal=4.5.3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 3, 2005
CVE Published
07:03 PM
Dec 4, 2005
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3974?
CVE-2005-3974 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2005-3974?
To fix CVE-2005-3974, upgrade to Drupal version 4.6.4 or above if you are using affected versions.
3
Which versions of Drupal are affected by CVE-2005-3974?
CVE-2005-3974 affects Drupal versions 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3.
4
Can CVE-2005-3974 allow unauthorized access to user profiles?
Yes, CVE-2005-3974 allows remote attackers to bypass the "access user profiles" permission.
5
Is CVE-2005-3974 related to PHP versions?
Yes, CVE-2005-3974 specifically affects Drupal when running on PHP5.