First Name
Marco
Last Name
Mosetti
Birthday
10/12/1973
On Saturday 24 of January we are going to upgrade mosettiStudios website to Drupal release 6.9. It means that for some hours during that day the website will not be reachable. We apologize from now for the inconvenience.This is what is stated on drupal.org website:
SA-CORE-2009-001 Drupal core - Multiple vulnerabilities
Gábor Hojtsy - January 15, 2009 - 00:00
- Advisory ID: DRUPAL-SA-CORE-2009-001
- Project: Drupal core
- Versions: 5.x and 6.x
- Date: 2009-January-14
- Security risk: Moderately Critical
- Exploitable from: Remote
- Vulnerability: Multiple vulnerabilities
Multiple vulnerabilities and weaknesses were discovered in Drupal.
Access Bypass
The Content Translation module for Drupal 6.x enables users to make a translation of an existing item of content (a node). In that process the existing node's content is copied into the new node's submission form.
The module contains a flaw that allows a user with the 'translate content' permission to potentially bypass normal viewing access restrictions, for example allowing the user to see the content of unpublished nodes even if they do not have permission to view unpublished nodes.
This issue only affects Drupal 6.x.
Validation Bypass
When user profile pictures are enabled, the default user profile validation function will be bypassed, possibly allowing invalid user names or e-mail addresses to be submitted.
This issue only affects Drupal 6.x.
Hardening against SQL injection
A parameter passed into the node access API was not properly escaped or validated before being used in SQL queries. While there is no direct risk of SQL injection from Drupal core, it's possible that this could have presented a risk in combination with a contributed module. Additional validation has been added to eliminate this risk.
This issue affects both Drupal 5.x and Drupal 6.x.
Thanks
mosettiStudios Team