PT-2019-6539 · Drupal · Drupal
Jan Lieskovsky
·
Publicado
2019-11-07
·
Atualizado
2021-04-30
·
CVE-2010-2250
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 5.x and 6.x before 6.16
Description
The issue allows an attacker to perform a cross-site scripting attack by crafting a URL, as a user-supplied value is used in output during site installation.
Recommendations
For versions 5.x and 6.x before 6.16, update to version 6.16 or later to resolve the issue.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal