Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1958

Опубликовано: 21 июн. 2010
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:quicksketch:filefield:5.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.0:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.1:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.2:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:rc2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:rc3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:rc4:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.4:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:beta3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.1:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.2:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.3:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.5:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.x-dev:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00269
Низкий

2.1 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).

EPSS

Процентиль: 50%
0.00269
Низкий

2.1 Low

CVSS2

Дефекты

CWE-79