CVE-2009-3920 Information

Share on:

Description

An administration page in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal does not perform the expected access control which allows remote attackers to read log information via unspecified vectors.

Reference

http://drupal.org/node/623506 http://drupal.org/node/623546 http://osvdb.org/59677 http://secunia.com/advisories/37287 http://www.securityfocus.com/bid/36927 https://exchange.xforce.ibmcloud.com/vulnerabilities/54153