CVE-2012-2303
18.07.2012, 18:55
The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.Enginsight
Vendor | Product | Version |
---|---|---|
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.0:x |
florian_weber | spaces | 6.x-3.1:x |
florian_weber | spaces | 6.x-3.2:x |
florian_weber | spaces | 6.x-3.3:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References