{"api_version":"1","generated_at":"2026-07-23T10:15:56+00:00","cve":"CVE-2007-3690","urls":{"html":"https://cve.report/CVE-2007-3690","api":"https://cve.report/api/cve/CVE-2007-3690.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3690","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3690"},"summary":{"title":"CVE-2007-3690","description":"The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-11 17:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/25999","name":"http://secunia.com/advisories/25999","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Forward Module Access Restriction Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/158025","name":"http://drupal.org/node/158025","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"forward 5.x-1.0 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/158022","name":"http://drupal.org/node/158022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"forward 4.7.x-1.1 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/152806","name":"http://drupal.org/node/152806","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Forward  - Access bypass | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/37896","name":"http://osvdb.org/37896","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/24862","name":"http://www.securityfocus.com/bid/24862","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Multiple Security Bypass Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2469","name":"http://www.vupen.com/english/advisories/2007/2469","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35318","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35318","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3690","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3690","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3690","vulnerable":"1","versionEndIncluding":"4.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"forward_module","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3690","vulnerable":"1","versionEndIncluding":"5.x-1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"forward_module","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:28:52.324Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"forward-url-security-bypass(35318)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35318"},{"name":"25999","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25999"},{"name":"ADV-2007-2469","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2469"},{"name":"24862","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24862"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/152806"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/158022"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/158025"},{"name":"37896","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37896"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"forward-url-security-bypass(35318)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35318"},{"name":"25999","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25999"},{"name":"ADV-2007-2469","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2469"},{"name":"24862","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24862"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/152806"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/158022"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/158025"},{"name":"37896","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37896"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3690","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"forward-url-security-bypass(35318)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35318"},{"name":"25999","refsource":"SECUNIA","url":"http://secunia.com/advisories/25999"},{"name":"ADV-2007-2469","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2469"},{"name":"24862","refsource":"BID","url":"http://www.securityfocus.com/bid/24862"},{"name":"http://drupal.org/node/152806","refsource":"CONFIRM","url":"http://drupal.org/node/152806"},{"name":"http://drupal.org/node/158022","refsource":"CONFIRM","url":"http://drupal.org/node/158022"},{"name":"http://drupal.org/node/158025","refsource":"CONFIRM","url":"http://drupal.org/node/158025"},{"name":"37896","refsource":"OSVDB","url":"http://osvdb.org/37896"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3690","datePublished":"2007-07-11T17:00:00.000Z","dateReserved":"2007-07-11T00:00:00.000Z","dateUpdated":"2024-08-07T14:28:52.324Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-11 17:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:forward_module:*:*:*:*:*:*:*:*","versionEndIncluding":"4.7","matchCriteriaId":"53DD8ACA-D5BC-4884-9381-60C651B540AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:forward_module:*:*:*:*:*:*:*:*","versionEndIncluding":"5.x-1.1","matchCriteriaId":"FE2FCC53-05F2-4953-9F93-8C3B6FFC900F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3690","Ordinal":"1","Title":"CVE-2007-3690","CVE":"CVE-2007-3690","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3690","Ordinal":"1","NoteData":"The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.","Type":"Description","Title":"CVE-2007-3690"},{"CveYear":"2007","CveId":"3690","Ordinal":"2","NoteData":"2007-07-11","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3690","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}