PT-2008-5100 · Drupal · Drupal
Tomas Hoger
·
Publicado
2008-08-27
·
Atualizado
2017-08-08
·
CVE-2008-3741
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 5.x before 5.10
Drupal versions 6.x before 6.4
Description
The issue allows remote authenticated users to conduct cross-site scripting (XSS) attacks. This is achieved by uploading files containing arbitrary web script or HTML, as the private filesystem trusts the MIME type sent by a web browser.
Recommendations
For Drupal versions 5.x before 5.10, update to version 5.10 or later.
For Drupal versions 6.x before 6.4, update to version 6.4 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal