Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 安全漏洞
Vulnerability Description
Drupal是Drupal社区的一套使用PHP语言开发的开源内容管理系统。 Drupal 6.2之前的6版本中存在安全漏洞。该漏洞源于菜单系统包含不正确的菜单设置,远程攻击者可以编辑任意用户的profile pages和从跟踪装置页和博客页中获得敏感信息(与缺少对"访问内容"许可的检查有关);拥有管理员页面查看权限的远程认证用户编辑内容类型。
CVSS Information
N/A
Vulnerability Type
N/A