Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Greggleson

Researcher fromDrupal Security Team
#50853of 53,622
4.3Total CVSS
Vulnerabilities · 1
PT-2009-5923
4.3
2009-10-09
Drupal · Browscap · CVE-2009-3651
**Name of the Vulnerable Software and Affected Versions** Browscap versions prior to 5.x-1.1 Browscap versions prior to 6.x-1.1 **Description** A cross-site scripting (XSS) issue exists in the Monitor browsers' feature of the Browscap module for Drupal. This issue allows remote attackers to inject arbitrary web script or HTML via the `User-Agent` HTTP header. **Recommendations** For Browscap versions prior to 5.x-1.1, update to version 5.x-1.1 or later. For Browscap versions prior to 6.x-1.1, update to version 6.x-1.1 or later.