If you have 'administer comments' privilege, try comment/edit/xx or comment/delete/xx, where xx is a non-existent comment. hm...

The attached patch tries to fix this.

Comments

dries’s picture

Status: Needs review » Needs work

I think it is better to fix this inside comment_edit() et al. We already perform access checks in those functions and therefore might be able to save a database query. Could you explore that path? Thanks.

ricabrantes’s picture

Version: x.y.z » 7.x-dev

This bug is active in d5 and d6, Moving to new version..

gpk’s picture

Just hit this in 6.14...

sivaji_ganesh_jojodae’s picture

Status: Needs work » Closed (duplicate)

This is a duplicate of #329023: comment.module should check for valid commend id on comment/edit/* and the issue reported here is already fixed for D7.