Drupal Permissions Privileges and Access Controls Vulnerability - CVE-2010-3093 - Vulnerability Database

Drupal Permissions Privileges and Access Controls Vulnerability - CVE-2010-3093

Low
Reference: CVE-2010-3093
Title: Drupal Permissions Privileges and Access Controls Vulnerability
Overview:

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL related to an quotunpublishing bypassquot issue.