PT-2010-3733 · Drupal · Drupal Storm

Publicado

2010-06-01

·

Atualizado

2017-08-17

·

CVE-2010-2123

CVSS v2.0

2.1

Baixa

VetorAV:N/AC:H/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal Storm module versions 5.x through 6.x-1.32
Description The issue allows remote authenticated users with certain module privileges to inject arbitrary web script or HTML. This can be achieved via various parameters in different actions to index.php, including fullname, address, city, provstate, phone, taxid, name, stepno, title, and unspecified parameters in stormproject actions.
Recommendations For Drupal Storm module versions 5.x through 6.x-1.32, update to version 6.x-1.33 or later to resolve the issue.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2123

Produtos afetados

Drupal Storm