Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x prior to 5.x-1.17 and 6.x prior to 6.x-1.6, a module for Drupal, allows remote attackers, with "create content displayed by the Bibliography module" permissions, to inject arbitrary web script or HTML via a title.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
drupal drupal |
||
ron_jerome bibliography 5.x-1.3 |
||
ron_jerome bibliography 5.x-1.4 |
||
ron_jerome bibliography 5.x-1.5 |
||
ron_jerome bibliography 5.x-1.6 |
||
ron_jerome bibliography 6.x-1.x-dev |
||
ron_jerome bibliography 6.x-1.0-beta2 |
||
ron_jerome bibliography 6.x-1.0-beta3 |
||
ron_jerome bibliography 6.x-1.0-beta4 |
||
ron_jerome bibliography 6.x-1.0-beta5 |
||
ron_jerome bibliography 6.x-1.0 |
||
ron_jerome bibliography 5.x-1.11 |
||
ron_jerome bibliography 5.x-1.12 |
||
ron_jerome bibliography 5.x-1.13 |
||
ron_jerome bibliography 5.x-1.14 |
||
ron_jerome bibliography 6.x-1.1 |
||
ron_jerome bibliography 6.x-1.2 |
||
ron_jerome bibliography 6.x-1.3 |
||
ron_jerome bibliography 5.x-1.1 |
||
ron_jerome bibliography 5.x-1.8 |
||
ron_jerome bibliography 5.x-1.10 |
||
ron_jerome bibliography 5.x-1.15 |
||
ron_jerome bibliography 5.x-1.x-dev |
||
ron_jerome bibliography 6.x-1.0-beta6 |
||
ron_jerome bibliography 6.x-1.0-beta8 |
||
ron_jerome bibliography 6.x-1.5 |
||
ron_jerome bibliography 5.x-1.0 |
||
ron_jerome bibliography 5.x-1.2 |
||
ron_jerome bibliography 5.x-1.7 |
||
ron_jerome bibliography 5.x-1.9 |
||
ron_jerome bibliography 5.x-1.16 |
||
ron_jerome bibliography 6.x-1.0-beta1 |
||
ron_jerome bibliography 6.x-1.0-beta7 |
||
ron_jerome bibliography 6.x-1.0-beta9 |
||
ron_jerome bibliography 6.x-1.4 |