First published: Tue Jul 16 2013(Updated: )
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =6.0 | |
Drupal Drupal | =6.0-beta1 | |
Drupal Drupal | =6.0-beta2 | |
Drupal Drupal | =6.0-beta3 | |
Drupal Drupal | =6.0-beta4 | |
Drupal Drupal | =6.0-dev | |
Drupal Drupal | =6.0-rc1 | |
Drupal Drupal | =6.0-rc2 | |
Drupal Drupal | =6.0-rc3 | |
Drupal Drupal | =6.0-rc4 | |
Drupal Drupal | =6.1 | |
Drupal Drupal | =6.2 | |
Drupal Drupal | =6.3 | |
Drupal Drupal | =6.4 | |
Drupal Drupal | =6.5 | |
Drupal Drupal | =6.6 | |
Drupal Drupal | =6.7 | |
Drupal Drupal | =6.8 | |
Drupal Drupal | =6.9 | |
Drupal Drupal | =6.10 | |
Drupal Drupal | =6.11 | |
Drupal Drupal | =6.12 | |
Drupal Drupal | =6.13 | |
Drupal Drupal | =6.14 | |
Drupal Drupal | =6.15 | |
Drupal Drupal | =6.16 | |
Drupal Drupal | =6.17 | |
Drupal Drupal | =6.18 | |
Drupal Drupal | =6.19 | |
Drupal Drupal | =6.20 | |
Drupal Drupal | =6.21 | |
Drupal Drupal | =6.22 | |
Drupal Drupal | =6.23 | |
Drupal Drupal | =6.24 | |
Drupal Drupal | =6.25 | |
Drupal Drupal | =6.26 | |
Drupal Drupal | =6.27 | |
Drupal Drupal | =7.0 | |
Drupal Drupal | =7.0-alpha1 | |
Drupal Drupal | =7.0-alpha2 | |
Drupal Drupal | =7.0-alpha3 | |
Drupal Drupal | =7.0-alpha4 | |
Drupal Drupal | =7.0-alpha5 | |
Drupal Drupal | =7.0-alpha6 | |
Drupal Drupal | =7.0-alpha7 | |
Drupal Drupal | =7.0-beta1 | |
Drupal Drupal | =7.0-beta2 | |
Drupal Drupal | =7.0-beta3 | |
Drupal Drupal | =7.0-dev | |
Drupal Drupal | =7.0-rc1 | |
Drupal Drupal | =7.0-rc2 | |
Drupal Drupal | =7.0-rc3 | |
Drupal Drupal | =7.0-rc4 | |
Drupal Drupal | =7.1 | |
Drupal Drupal | =7.2 | |
Drupal Drupal | =7.3 | |
Drupal Drupal | =7.4 | |
Drupal Drupal | =7.5 | |
Drupal Drupal | =7.6 | |
Drupal Drupal | =7.7 | |
Drupal Drupal | =7.8 | |
Drupal Drupal | =7.9 | |
Drupal Drupal | =7.10 | |
Drupal Drupal | =7.11 | |
Drupal Drupal | =7.12 | |
Drupal Drupal | =7.13 | |
Drupal Drupal | =7.14 | |
Drupal Drupal | =7.15 | |
Drupal Drupal | =7.16 | |
Drupal Drupal | =7.17 | |
Drupal Drupal | =7.18 | |
Drupal Drupal | =7.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.