Описание
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | ignored | end of life |
maverick | not-affected | 6.18-1ubuntu1 |
natty | not-affected | |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
raring | not-affected | |
saucy | DNE |
Показывать по
Ссылки на источники
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...
Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
4.3 Medium
CVSS2
6.1 Medium
CVSS3