Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dries

#30406of 53,624
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2006-3227
4.3
2006-05-09
Drupal · Drupal · CVE-2006-2260
**Name of the Vulnerable Software and Affected Versions** Drupal versions 4.5 through 4.6 **Description** A cross-site scripting (XSS) issue exists in the project module, allowing remote attackers to inject arbitrary web script or HTML. The exact attack vectors are not specified. **Recommendations** For versions 4.5 and 4.6, update to a newer version to mitigate the risk, as these versions are affected by the XSS vulnerability in the project module.
PT-2005-1724
4.3
2005-03-07
Drupal · Drupal · CVE-2005-0682
**Name of the Vulnerable Software and Affected Versions** Drupal versions prior to 4.5.2 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via certain inputs. This is due to a vulnerability in the common.inc file. **Recommendations** For versions prior to 4.5.2, update to version 4.5.2 or later to resolve the issue.