Описание
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
Ссылки
- PatchVendor Advisory
- Third Party Advisory
- PatchThird Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party Advisory
- PatchThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:drupal:drupal:6.0:*:*:*:*:*:*:*
EPSS
Процентиль: 61%
0.00416
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
ubuntu
больше 17 лет назад
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
debian
больше 17 лет назад
The Drupal.checkPlain function in Drupal 6.0 only escapes the first in ...
github
около 3 лет назад
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
EPSS
Процентиль: 61%
0.00416
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-79