CVE-2010-2472
Summary
| CVE | CVE-2010-2472 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-07 19:15:00 UTC |
| Updated | 2019-11-13 16:14:00 UTC |
| Description | Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE Request -- Drupal v6.16 / v5.22 SA-CORE-2010-001 | MLIST | www.openwall.com | Mailing List, Third Party Advisory |
| SA-CORE-2010-001 - Drupal core - Multiple vulnerabilities | drupal.org | CONFIRM | www.drupal.org | Patch, Vendor Advisory |
| CVE-2010-2472 | MISC | security-tracker.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.