CVE-2006-2833
Summary
| CVE | CVE-2006-2833 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-06 00:02:00 UTC |
| Updated | 2018-10-18 16:43:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Debian -- Security Information -- DSA-1125-2 drupal | DEBIAN | www.debian.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Debian update for drupal - Advisories - Secunia | SECUNIA | secunia.com | |
| Drupal Taxonomy Module Cross-Site Scripting Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| drupal.org/files/sa-2006-008/4.6.7.patch | CONFIRM | drupal.org | Patch |
| Drupal Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | Patch |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| XSS Vulnerability in taxonomy module | drupal.org | CONFIRM | drupal.org | Patch |
| Drupal 4.6.8 / 4.7.2 fixes XSS issue - CXSecurity.com | SREASON | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.