Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.
References
Link | Resource |
---|---|
http://osvdb.org/63589 | |
http://www.securityfocus.com/bid/39304 | Patch |
http://drupal.org/node/764906 | Patch |
http://secunia.com/advisories/39361 | Vendor Advisory |
http://drupal.org/node/764998 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-04-26 11:30
Updated : 2010-04-26 21:00
NVD link : CVE-2010-1530
Mitre link : CVE-2010-1530
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
reyero
- i18n
drupal
- drupal