CVE-2007-0506
Summary
| CVE | CVE-2007-0506 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-26 00:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests. |
Risk And Classification
Primary CVSS: v2.0 6 from [email protected]
AV:N/AC:M/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Project | 4.6 | All | All | All |
| Application | Drupal | Project | 4.6_1.1 | All | All | All |
| Application | Drupal | Project | 4.7 | All | All | All |
| Application | Drupal | Project | 4.7_1.1 | All | All | All |
| Application | Drupal | Project | 4.7_2.1 | All | All | All |
| Application | Drupal | Project | 5.0 | All | dev | All |
| Application | Drupal | Project Issue Tracking Module | 4.7 | All | All | All |
| Application | Drupal | Project Issue Tracking Module | 4.7_1.1 | All | All | All |
| Application | Drupal | Project Issue Tracking Module | 4.7_2.1 | All | All | All |
| Application | Drupal | Project Issue Tracking Module | 5.0 | All | dev | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/32135 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Drupal Project Issue Tracking Module Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Project and Project issue tracking - Multiple vulnerabilities | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.