CVE-2009-4526 Information

Share on:

Description

The Send by e-mail sub-module in the Print (aka Printer e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9 a module for Drupal does not properly enforce privilege requirements which allows remote attackers to read page titles by requesting a \Send to friend\ form.

Reference

http://drupal.org/node/604804 http://drupal.org/node/604806 http://drupal.org/node/604808 http://osvdb.org/58951 http://secunia.com/advisories/37059 http://www.securityfocus.com/bid/36707 http://www.vupen.com/english/advisories/2009/2922