Security Advisory
CVE-2013-1859
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors.