The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors.Referenceshttp://secunia.com/advisories/37202http://drupal.org/node/617480http://drupal.org/node/617494http://www.vupen.com/english/advisories/2009/3090http://www.securityfocus.com/bid/36879