Boletines de Vulnerabilidades |
SA-CORE-2009-009 - Drupal Core - Cross site scripting |
|
| Software afectado | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2009-009Project: Drupal coreVersion: 5.x, 6.xDate: 2009-December-16Security risk: Not criticalExploitable from: RemoteVulnerability: Cross site scriptingDescriptionMultiple vulnerabilities were discovered in Drupal.Contact category name cross-site scriptingThe Contact module does not correctly handle certain user input when displaying category information. Users privileged to create contact categories can insert arbitrary HTML and script code into the contact module More info: https://www.drupal.org/node/661586 |
|














