Security Advisory

CVE-2007-0506

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-01-26 00:00:00
Last updated 2024-08-07 12:19:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.