Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Book模块‘printer friendly version’功能权限许可和访问控制漏洞
Vulnerability Description
Book是用于Drupal中的一个扩展模块,该模块的作用是在电子书浏览器中添加一个书导航块。Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal 6.28之前的6.x版本和7.19之前的7.x版本中的Book模块中的‘printer friendly version’功能中存在访问绕过漏洞,该漏洞源于程序没有正确限制对本书大纲部分的节点访问。远程经过授权的攻击者可利用该漏洞以‘访问printer-friendly version’的权限读取节点标题,也可能读
CVSS Information
N/A
Vulnerability Type
N/A