Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-5596

Опубликовано: 19 окт. 2007
Источник: debian
EPSS Низкий

Описание

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal5fixed5.3-1package
drupalfixed4.7.8-1package

EPSS

Процентиль: 68%
0.00576
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

nvd
больше 18 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

github
почти 4 года назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

EPSS

Процентиль: 68%
0.00576
Низкий