Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.
References
Link | Resource |
---|---|
http://drupal.org/node/829840 | Patch Vendor Advisory |
http://www.openwall.com/lists/oss-security/2010/12/16/7 | Patch |
http://www.openwall.com/lists/oss-security/2010/12/22/1 | Patch |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2010-12-23 10:00
Updated : 2010-12-23 10:00
NVD link : CVE-2010-4520
Mitre link : CVE-2010-4520
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
drupal
- drupal
earl_miles
- views