Description
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2005-2678)
WordPress Plugin Ninja Popups Multiple Vulnerabilities (4.5.3)
WordPress Plugin Advanced Post Type Ratings Cross-Site Scripting (1.01)
WordPress Plugin SP Project & Document Manager Unspecified Vulnerability (2.6.2.5)
Apache HTTP Server CVE-2007-3304 Vulnerability (CVE-2007-3304)