CVE-2012-1643
https://notcve.org/view.php?id=CVE-2012-1643
The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers to modify access permissions via unspecified vectors. El módulo Faster Persmissions v7.x-2.x anterior a v7.x-1.2 para Drupal no comprueba los permisos "administer permissions", lo cual permite a atacantes remotos modificar los permisos de acceso a través de vectores desconocidos. • http://drupal.org/node/1441556 http://drupalcode.org/project/fp.git/commitdiff/39e7587 http://secunia.com/advisories/48019 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/79316 https://drupal.org/node/1441448 • CWE-264: Permissions, Privileges, and Access Controls •