>> Drupal Menu Security Bypass and Data Manipulation Vulnerability
Title : Drupal Menu Security Bypass and Data Manipulation Vulnerability VUPEN ID : VUPEN/ADV-2008-1185 CVE ID : CVE-2008-1729
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-10
Technical Description
A vulnerability has been identified in Drupal, which could be exploited by attackers to bypass security restrictions and manipulate certain data. This issue is caused by errors in the menu system that does not properly validate user permissions, which could be exploited by attackers to edit profile pages and content types, or gain knowledge of sensitive information via the tracker and blog pages.