Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.
| Software | From | Fixed in |
|---|---|---|
drupal / drupal
|
4.6 | 4.6.x |
drupal / drupal
|
4.5.4 | 4.5.4.x |
drupal / drupal
|
4.5.2 | 4.5.2.x |
drupal / drupal
|
4.6.2 | 4.6.2.x |
drupal / drupal
|
4.5.1 | 4.5.1.x |
drupal / drupal
|
4.6.3 | 4.6.3.x |
drupal / drupal
|
4.5.5 | 4.5.5.x |
drupal / drupal
|
4.5 | 4.5.x |
drupal / drupal
|
4.6.1 | 4.6.1.x |
drupal / drupal
|
4.5.3 | 4.5.3.x |