CVE-2006-1227: Medium severity Drupal Drupal vulnerability
Published Mar 14, 2006
·Updated
Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.
Affected Software
14 affected components
Drupal Drupal=4.6.0
Drupal Drupal=4.6.5
Drupal Drupal=4.5.4
Drupal Drupal=4.5.0
Drupal Drupal=4.5.2
Drupal Drupal=4.6.2
Drupal Drupal=4.5.7
Drupal Drupal=4.5.1
Drupal Drupal=4.6.3
Drupal Drupal=4.6.4
Drupal Drupal=4.5.5
Drupal Drupal=4.6.1
Drupal Drupal=4.5.3
Drupal Drupal=4.5.6
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 14, 2006
CVE Published
07:06 PM
Mar 15, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1227?
The severity of CVE-2006-1227 is classified as moderate due to the potential for unauthorized access to administrator pages.
2
How do I fix CVE-2006-1227?
To fix CVE-2006-1227, upgrade to Drupal version 4.5.8 or 4.6.8 or later.
3
What versions of Drupal are affected by CVE-2006-1227?
CVE-2006-1227 affects Drupal versions 4.5.0 through 4.5.7 and 4.6.0 through 4.6.7.
4
What is the impact of CVE-2006-1227?
The impact of CVE-2006-1227 allows remote attackers to bypass access control, potentially revealing sensitive administrator interfaces.
5
Is there a workaround for CVE-2006-1227?
There are no reliable workarounds for CVE-2006-1227; applying the update is the recommended action.