2.6
CVSSv2

CVE-2013-0181

Published: 27/03/2013 Updated: 29/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x prior to 7.x-1.4 for Drupal, when using certain backends and facets, allows remote malicious users to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

thomas_seidl search_api 7.x-1.0

thomas_seidl search_api 7.x-1.3

thomas_seidl search_api 7.x-1.x

thomas_seidl search_api 7.x-1.2

thomas_seidl search_api 7.x-1.1