Drupal Color Module HTML Injection Vulnerability
BID:47992
Info
Drupal Color Module HTML Injection Vulnerability
| Bugtraq ID: | 47992 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2011 12:00AM |
| Updated: | Apr 13 2015 10:23PM |
| Credit: | Kasper Lindgaard, Secunia Research. |
| Vulnerable: |
Drupal Drupal 7.0 Alpha7 Drupal Drupal 7.0 Alpha6 Drupal Drupal 7.0 Alpha5 Drupal Drupal 7.0 Alpha4 Drupal Drupal 7.0 Alpha3 Drupal Drupal 7.0 Alpha2 Drupal Drupal 7.0 Alpha1 Drupal Drupal 6.2 Drupal Drupal 6.18 Drupal Drupal 6.17 Drupal Drupal 6.16 Drupal Drupal 6.15 Drupal Drupal 6.15 Drupal Drupal 6.14 Drupal Drupal 6.13 Drupal Drupal 6.12 Drupal Drupal 6.11 Drupal Drupal 6.10 Drupal Drupal 6.1 Drupal Drupal 6.0 |
| Not Vulnerable: |
Drupal Drupal 7.2 Drupal Drupal 7.1 Drupal Drupal 6.22 Drupal Drupal 6.21 |
Exploit / POC
Drupal Color Module HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Drupal Color Module HTML Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Drupal Color Module HTML Injection Vulnerability
References:
References: