Unrated severityNVD Advisory· Published Dec 31, 2009· Updated Apr 23, 2026
CVE-2009-4520
CVE-2009-4520
Description
The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access restrictions and read comments by using the autocomplete path.
Affected products
6cpe:2.3:a:kristof_de_jaeger:commentreference:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:kristof_de_jaeger:commentreference:*:*:*:*:*:*:*:*range: <=5.x-1.1
- cpe:2.3:a:kristof_de_jaeger:commentreference:5.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:kristof_de_jaeger:commentreference:5.x-1.x-dev:*:*:*:*:*:*:*
- cpe:2.3:a:kristof_de_jaeger:commentreference:6.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:kristof_de_jaeger:commentreference:6.x-1.1:*:*:*:*:*:*:*
- cpe:2.3:a:kristof_de_jaeger:commentreference:6.x-1.x-dev:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- drupal.org/node/617380nvdPatchVendor Advisory
- www.securityfocus.com/bid/36863nvdPatch
- www.vupen.com/english/advisories/2009/3084nvdPatchVendor Advisory
- secunia.com/advisories/37206nvdVendor Advisory
News mentions
0No linked articles in our index yet.