if db module is enabled basically anyone can view the database content if adresses directly.
Eg. user data if this module is enabled can be viewed at address

http://www.yourdrupalsite.com/?q=admin/database/table/users/view

Comments

chx’s picture

Fixed. Both 4.5 and HEAD.

chx’s picture

4.6 too. Checked 4.4 -- it is OK.

chx’s picture

sepeck’s picture

tested patched version succesful on 4.5 and CVS

jeremy’s picture

Thanks for finding the bug, and for the quick followup. The fix checked in by chx to 4.5, 4.6 and HEAD is correct. Please be sure to upgrade your dba module quickly!

Anonymous’s picture