{"api_version":"1","generated_at":"2026-07-23T08:14:18+00:00","cve":"CVE-2007-3689","urls":{"html":"https://cve.report/CVE-2007-3689","api":"https://cve.report/api/cve/CVE-2007-3689.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3689","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3689"},"summary":{"title":"CVE-2007-3689","description":"The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-11 17:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/2470","name":"http://www.vupen.com/english/advisories/2007/2470","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/152804","name":"http://drupal.org/node/152804","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Print - Access bypass | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/158032","name":"http://drupal.org/node/158032","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"print 5.x-1.2 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37897","name":"http://osvdb.org/37897","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/24862","name":"http://www.securityfocus.com/bid/24862","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Multiple Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://drupal.org/node/158029","name":"http://drupal.org/node/158029","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"print 4.7.x-1.0 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35314","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35314","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25978","name":"http://secunia.com/advisories/25978","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Print Module Access Restriction Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3689","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3689","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3689","vulnerable":"1","versionEndIncluding":"4.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"print_module","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3689","vulnerable":"1","versionEndIncluding":"5.x-1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"print_module","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:28:51.606Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/158032"},{"name":"25978","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25978"},{"name":"ADV-2007-2470","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2470"},{"name":"24862","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24862"},{"name":"printfriendlypages-url-security-bypass(35314)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35314"},{"name":"37897","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37897"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/158029"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/152804"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/158032"},{"name":"25978","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25978"},{"name":"ADV-2007-2470","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2470"},{"name":"24862","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24862"},{"name":"printfriendlypages-url-security-bypass(35314)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35314"},{"name":"37897","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37897"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/158029"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/152804"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3689","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://drupal.org/node/158032","refsource":"CONFIRM","url":"http://drupal.org/node/158032"},{"name":"25978","refsource":"SECUNIA","url":"http://secunia.com/advisories/25978"},{"name":"ADV-2007-2470","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2470"},{"name":"24862","refsource":"BID","url":"http://www.securityfocus.com/bid/24862"},{"name":"printfriendlypages-url-security-bypass(35314)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35314"},{"name":"37897","refsource":"OSVDB","url":"http://osvdb.org/37897"},{"name":"http://drupal.org/node/158029","refsource":"CONFIRM","url":"http://drupal.org/node/158029"},{"name":"http://drupal.org/node/152804","refsource":"CONFIRM","url":"http://drupal.org/node/152804"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3689","datePublished":"2007-07-11T17:00:00.000Z","dateReserved":"2007-07-11T00:00:00.000Z","dateUpdated":"2024-08-07T14:28:51.606Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-11 17:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:print_module:*:*:*:*:*:*:*:*","versionEndIncluding":"4.7","matchCriteriaId":"5000E29D-E826-4C77-B141-B8F483D837AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:print_module:*:*:*:*:*:*:*:*","versionEndIncluding":"5.x-1.1","matchCriteriaId":"54CC380C-A5C4-4B72-B0E4-201CBD4B238E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3689","Ordinal":"1","Title":"CVE-2007-3689","CVE":"CVE-2007-3689","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3689","Ordinal":"1","NoteData":"The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.","Type":"Description","Title":"CVE-2007-3689"},{"CveYear":"2007","CveId":"3689","Ordinal":"2","NoteData":"2007-07-11","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3689","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}