4.3
CVSSv2

CVE-2002-1806

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote malicious users to inject arbitrary web script or HTML via Javascript in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 4.0.0

Exploits

source: wwwsecurityfocuscom/bid/5801/info Problems with Drupal could allow an attacker to execute arbitrary script code in a vulnerable client Drupal fails to sufficiently filter potentially malicious HTML code from news posts As a result, when a user views a news posting that contains malicious HTML code, the code contained in the pos ...