Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-5596

Опубликовано: 19 окт. 2007
Источник: debian
EPSS Низкий

Описание

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal5fixed5.3-1package
drupalfixed4.7.8-1package

EPSS

Процентиль: 67%
0.00539
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

nvd
больше 17 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

github
около 3 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

EPSS

Процентиль: 67%
0.00539
Низкий