CVE

Id
55546  
CVE No.
CVE-2012-2303  
Status
Candidate  
Description
The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.  
Phase
Assigned (20120419)  
Votes
None (candidate not yet proposed)  
Comments