Description
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
Remediation
References
Related Vulnerabilities
WordPress Plugin VK Gallery TimThumb Arbitrary File Upload (1.1.0)
WordPress Plugin Pressbooks Cross-Site Scripting (2.4.2)
WordPress Plugin Two Way CHAT-Send or receive messages to your user Multiple Vulnerabilities (3.1.4)
WordPress Plugin Poll Maker SQL Injection (3.4.1)
WordPress Plugin Flexible Captcha Multiple Vulnerabilities (3.3)