Closed (outdated)
Project:
Drupal core
Version:
6.6
Component:
user.module
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
2 Oct 2008 at 08:28 UTC
Updated:
2 Mar 2016 at 22:18 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
sebdah commentedThis exists in Drupal 6.6 as well. The patch need to be reviewed. I don't really know how the filtering should be done here, so I made a sample :/.
Comment #2
chx commentedAs ingo86 says, it could lead to a priviledge escalation.... however if you can get to this page then you already have every priviledge you wanted. You can easily give yourself enough access to run PHP code and then do whatever you wanted. I do not see the need to fix this.
Comment #3
dpearcefl commentedIs this still an issue using current Drupal 6?