Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-4064

Опубликовано: 30 июл. 2007
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 4.3

Описание

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

РелизСтатусПримечание
dapper

not-affected

devel

DNE

edgy

not-affected

feisty

released

5.1-0ubuntu2.1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 58%
0.00363
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

debian
почти 18 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x befo ...

github
около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

EPSS

Процентиль: 58%
0.00363
Низкий

4.3 Medium

CVSS2