2.6
CVSSv2

CVE-2006-2832

Published: 06/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x prior to 4.6.8 and 4.7.x prior to 4.7.2 allows remote malicious users to inject arbitrary web script or HTML via the uploaded filename.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 4.6.5

drupal drupal 4.6.6

drupal drupal 4.6.3

drupal drupal 4.6.4

drupal drupal 4.6

drupal drupal 4.6.0

drupal drupal 4.6.7

drupal drupal 4.7.0

drupal drupal 4.6.1

drupal drupal 4.6.2

drupal drupal 4.7.1

Vendor Advisories

The Drupal update in DSA 1125 contained a regression This update corrects this flaw For completeness, the original advisory text below: Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web script The Common Vulnerabilities and Exposures project identifies the follow ...