Description
|
|
Multiple vulnerabilities have been identified in Drupal, which could be exploited by attackers to bypass security restrictions or disclose sensitive information.
The first issue is caused by an error when running the application on a server configured for IP-based virtual hosts, which could be exploited to include and execute arbitrary files outside the root directory.
The second vulnerability is caused by an input validation error when processing titles of book pages, which could allow malicious users with "create book content" permissions or the permission to edit any node in the book hierarchy to execute arbitrary scripting code.
|