A deficiency in the user module allowed users who had been blocked by access rules to continue logging into the site under certain conditions.
Part of security release SA-2008-060
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4