Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x prior to 6.x-2.3 for Drupal, when debug mode is enabled, allows remote malicious users to inject arbitrary web script or HTML via vectors related to the "$conf variable in settings.php."
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
john_franklin advertisement 6.x-2.0 |
||
john_franklin advertisement 6.x-2.1 |
||
john_franklin advertisement 6.x-2.x |
||
john_franklin advertisement 6.x-2.0-rc1 |
||
john_franklin advertisement 6.x-2.2 |
||
john_franklin advertisement 6.x-2.3 |