Advertisement






Drupal 4.6.6 / 4.5.8 fixes XSS issue

CVE Category Price Severity
CWE-79 Not specified Medium
Author Risk Exploitation Type Date
Not specified Medium Remote 2006-03-23
Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006030073

Below is a copy:

------------------------------------------------------------------------
----
Drupal security advisory                                  DRUPAL-SA-2006-002
------------------------------------------------------------------------
----
Advisory ID:    DRUPAL-SA-2006-002
Project:        Drupal core
Date:           2006-03-13
Security risk:  less critical
Impact:         cross-site scripting
Where:          from remote
Vulnerability:  cross-site scripting
------------------------------------------------------------------------
----

Description
-----------
Some user input sanity checking was missing. This could lead to
possible cross-site scripting (XSS) attacks.

XSS can lead to user tracking and theft of accounts and services.

Versions affected
-----------------
All Drupal versions before 4.6.6.

Solution
--------
If you are running Drupal 4.5.x then upgrade to Drupal 4.5.8.
If you are running Drupal 4.6.x then upgrade to Drupal 4.6.6.

Contact
-------
The security contact for Drupal can be reached at security (at) drupal (dot) org [email concealed]
or using the form at http://drupal.org/contact.
More information is available from http://drupal.org/security or from
our security RSS feed http://drupal.org/security/rss.xml.

// Uwe Hermann, on behalf of the Drupal Security Team.
-- 
Uwe Hermann 
http://www.hermann-uwe.de
http://www.it-services-uh.de  | http://www.crazy-hacks.org 
http://www.holsham-traders.de | http://www.unmaintained-free-software.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFEFiPKXdVoV3jWIbQRAitTAKCIO3aOBy2sVVD2dBs5oSKSeVLLEQCfUWV/
jK6Eed6rQCK6YbKhp6E5XDE=
=aqzn
-----END PGP SIGNATURE-----

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum