Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-5021

Опубликовано: 22 июл. 2014
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal6removedpackage
drupal6end-of-lifesqueezepackage
drupal7fixed7.29-1package

Примечания

  • https://www.drupal.org/SA-CORE-2014-003

EPSS

Процентиль: 46%
0.00227
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

nvd
почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

EPSS

Процентиль: 46%
0.00227
Низкий