4.3
CVSSv2

CVE-2015-6665

Published: 24/08/2015 Updated: 24/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x prior to 7.39 and the Ctools module 6.x-1.x prior to 6.x-1.14 for Drupal allows remote malicious users to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 22

fedoraproject fedora 21

fedoraproject fedora 23

drupal drupal 7.0

drupal drupal 7.15

drupal drupal 7.11

drupal drupal 7.12

drupal drupal 7.2

drupal drupal 7.20

drupal drupal 7.27

drupal drupal 7.28

drupal drupal 7.36

drupal drupal 7.37

drupal drupal 7.x-dev

drupal drupal 7.16

drupal drupal 7.17

drupal drupal 7.23

drupal drupal 7.24

drupal drupal 7.30

drupal drupal 7.33

drupal drupal 7.6

drupal drupal 7.7

drupal drupal 7.1

drupal drupal 7.10

drupal drupal 7.18

drupal drupal 7.19

drupal drupal 7.25

drupal drupal 7.26

drupal drupal 7.34

drupal drupal 7.35

drupal drupal 7.8

drupal drupal 7.9

drupal drupal 7.13

drupal drupal 7.14

drupal drupal 7.21

drupal drupal 7.22

drupal drupal 7.29

drupal drupal 7.3

drupal drupal 7.38

drupal drupal 7.4

drupal drupal 7.5

chaos tool suite project ctools 6.x-1.0

chaos tool suite project ctools 6.x-1.3

chaos tool suite project ctools 6.x-1.4

chaos tool suite project ctools 6.x-1.5

chaos tool suite project ctools 6.x-1.11

chaos tool suite project ctools 6.x-1.12

chaos tool suite project ctools 6.x-1.8

chaos tool suite project ctools 6.x-1.9

chaos tool suite project ctools 6.x-1.13

chaos tool suite project ctools 6.x-1.2

chaos tool suite project ctools 6.x-1.x

chaos tool suite project ctools 6.x-1.1

chaos tool suite project ctools 6.x-1.6

chaos tool suite project ctools 6.x-1.7

Vendor Advisories

Several vulnerabilities were discovered in Drupal, a content management framework: CVE-2015-6658 The form autocomplete functionality did not properly sanitize the requested URL, allowing remote attackers to perform a cross-site scripting attack CVE-2015-6659 The SQL comment filtering system could allow a user with elevated per ...