Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 权限许可和访问控制问题漏洞
Vulnerability Description
Drupal是Drupal社区的一套使用PHP语言开发的开源内容管理系统。 Site Documentation Drupal module 5.x-1.8之前的5.x以及6.x-1.1之前的6.x存在权限许可和访问控制问题漏洞。远程认证用户可以通过杠杆化对列出表格的“访问内容”许可获得特权,以及从数据库中取得会话IDs。
CVSS Information
N/A
Vulnerability Type
N/A