{"api_version":"1","generated_at":"2026-07-23T05:00:35+00:00","cve":"CVE-2007-0506","urls":{"html":"https://cve.report/CVE-2007-0506","api":"https://cve.report/api/cve/CVE-2007-0506.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0506","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0506"},"summary":{"title":"CVE-2007-0506","description":"The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-26 00:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/32135","name":"http://osvdb.org/32135","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/22224","name":"http://www.securityfocus.com/bid/22224","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Project and Project Issues Tracking Modules Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/23887","name":"http://secunia.com/advisories/23887","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Project Issue Tracking Module Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31727","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31727","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0312","name":"http://www.vupen.com/english/advisories/2007/0312","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/112146","name":"http://drupal.org/node/112146","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Project and Project issue tracking - Multiple vulnerabilities | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0506","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0506","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project","cpe6":"4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project","cpe6":"4.6_1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project","cpe6":"4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project","cpe6":"4.7_1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project","cpe6":"4.7_2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project","cpe6":"5.0","cpe7":"*","cpe8":"dev","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project_issue_tracking_module","cpe6":"4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project_issue_tracking_module","cpe6":"4.7_1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project_issue_tracking_module","cpe6":"4.7_2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"project_issue_tracking_module","cpe6":"5.0","cpe7":"*","cpe8":"dev","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:19:30.350Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23887","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23887"},{"name":"22224","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22224"},{"name":"32135","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32135"},{"name":"ADV-2007-0312","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0312"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/112146"},{"name":"projecttracking-access-info-disclosure(31727)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31727"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"23887","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23887"},{"name":"22224","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22224"},{"name":"32135","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32135"},{"name":"ADV-2007-0312","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0312"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/112146"},{"name":"projecttracking-access-info-disclosure(31727)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31727"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0506","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23887","refsource":"SECUNIA","url":"http://secunia.com/advisories/23887"},{"name":"22224","refsource":"BID","url":"http://www.securityfocus.com/bid/22224"},{"name":"32135","refsource":"OSVDB","url":"http://osvdb.org/32135"},{"name":"ADV-2007-0312","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0312"},{"name":"http://drupal.org/node/112146","refsource":"CONFIRM","url":"http://drupal.org/node/112146"},{"name":"projecttracking-access-info-disclosure(31727)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31727"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0506","datePublished":"2007-01-26T00:00:00.000Z","dateReserved":"2007-01-25T00:00:00.000Z","dateUpdated":"2024-08-07T12:19:30.350Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-26 00:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project:4.6:*:*:*:*:*:*:*","matchCriteriaId":"FAD68C3C-298C-41C6-BC6E-D25EBCDAA11D"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project:4.6_1.1:*:*:*:*:*:*:*","matchCriteriaId":"CDC8AB64-19E1-4F38-994F-971E1B6268F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project:4.7:*:*:*:*:*:*:*","matchCriteriaId":"E105AA85-FA71-45D1-A7A2-6C07FFEA452D"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project:4.7_1.1:*:*:*:*:*:*:*","matchCriteriaId":"FE28E558-D90C-49E8-A472-7A37FBB49F4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project:4.7_2.1:*:*:*:*:*:*:*","matchCriteriaId":"BBE32A77-7098-4E5B-8B85-E6B8930D1FAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project:5.0:*:dev:*:*:*:*:*","matchCriteriaId":"F6D3BE9B-7223-403A-90F4-39AE94DE7EB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project_issue_tracking_module:4.7:*:*:*:*:*:*:*","matchCriteriaId":"80E74B2F-1EB1-462D-B970-339C8817C229"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project_issue_tracking_module:4.7_1.1:*:*:*:*:*:*:*","matchCriteriaId":"B7813534-EA9B-4A5E-B84E-D0D353EE9719"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project_issue_tracking_module:4.7_2.1:*:*:*:*:*:*:*","matchCriteriaId":"41B5AE16-B0D6-4E65-86BF-82EA5CD6F1B5"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:project_issue_tracking_module:5.0:*:dev:*:*:*:*:*","matchCriteriaId":"4A79A0F8-29F0-4393-8A44-83E804BC38EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"506","Ordinal":"1","Title":"CVE-2007-0506","CVE":"CVE-2007-0506","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"506","Ordinal":"1","NoteData":"The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.","Type":"Description","Title":"CVE-2007-0506"},{"CveYear":"2007","CveId":"506","Ordinal":"2","NoteData":"2007-01-25","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"506","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}