2.6
CVSSv2

CVE-2010-3022

Published: 16/08/2010 Updated: 17/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x prior to 5.x-1.3 and 6.x prior to 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths in a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal devel module

drupal devel module 6.x-1.19

drupal devel module 6.x-1.11

drupal devel module 6.x-1.10

drupal devel module 6.x-1.3

drupal devel module 6.x-1.1

drupal devel module 6.x-1.13

drupal devel module 6.x-1.12

drupal devel module 6.x-1.5

drupal devel module 6.x-1.4

drupal devel module 5.x-1.1

drupal devel module 5.x-1.0

drupal devel module 6.x-1.18

drupal devel module 6.x-1.17

drupal devel module 6.x-1.16

drupal devel module 6.x-1.9

drupal devel module 6.x-1.8

drupal devel module 6.x-1.0

drupal devel module 6.x-1.2

drupal devel module 6.x-1.15

drupal devel module 6.x-1.14

drupal devel module 6.x-1.7

drupal devel module 6.x-1.6

drupal devel module 5.x-1.3