CVE-2008-2271
16.05.2008, 12:54
The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database.Enginsight
Vendor | Product | Version |
---|---|---|
site_documentation_project | site_documentation | 5.x-1.0 ≤ 𝑥 < 5.x-1.8 |
site_documentation_project | site_documentation | 6.x-1.0 ≤ 𝑥 < 6.x-1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References