2.1
CVSSv2

CVE-2010-2158

Published: 07/06/2010 Updated: 08/06/2010
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x prior to 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

speedtech storm 5.x-1.10

speedtech storm 5.x-1.12

speedtech storm 5.x-1.4

speedtech storm 5.x-1.6

speedtech storm 5.x-1.13

speedtech storm 5.x-1.14

speedtech storm 5.x-1.2

speedtech storm 5.x-1.3

speedtech storm 5.x-1.8

speedtech storm 5.x-1.9

speedtech storm 5.x-1.x

speedtech storm 5.x-1.1

speedtech storm 5.x-1.11

speedtech storm 5.x-1.5

speedtech storm 5.x-1.7

speedtech storm 6.x-1.11

speedtech storm 6.x-1.31

speedtech storm 6.x-1.9

speedtech storm 6.x-1.x

speedtech storm 6.x-1.5

speedtech storm 6.x-1.7

speedtech storm 6.x-1.24

speedtech storm 6.x-1.26

speedtech storm 6.x-1.16

speedtech storm 6.x-1.18

speedtech storm 6.x-1.10

speedtech storm 6.x-1.1

speedtech storm 6.x-1.0

speedtech storm 6.x-1.32

speedtech storm 6.x-1.20

speedtech storm 6.x-1.21

speedtech storm 6.x-1.22

speedtech storm 6.x-1.23

speedtech storm 6.x-1.28

speedtech storm 6.x-1.27

speedtech storm 6.x-1.3

speedtech storm 6.x-1.29

speedtech storm 6.x-1.12

speedtech storm 6.x-1.13

speedtech storm 6.x-1.14

speedtech storm 6.x-1.15

speedtech storm 6.x-1.30

speedtech storm 6.x-1.8

speedtech storm 6.x-1.4

speedtech storm 6.x-1.6

speedtech storm 6.x-1.2

speedtech storm 6.x-1.25

speedtech storm 6.x-1.17

speedtech storm 6.x-1.19