PT-2006-7248 · Drupal · Drupal
Derek Wright
+1
·
Published
2006-12-20
·
Updated
2011-03-08
·
CVE-2006-6646
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Drupal Project Issue Tracking versions 4.7.x-1.0 through 4.7.x-2.0
Drupal Project versions 4.6.x-1.0, 4.7.x-1.0, 4.7.x-2.0
Description
The issue allows remote attackers to inject arbitrary web script or HTML via unspecified
parameters. This is possible because the check plain function is not used.Recommendations
For Drupal Project Issue Tracking versions 4.7.x-1.0 through 4.7.x-2.0, update to ensure the
check plain function is utilized for all parameters.
For Drupal Project versions 4.6.x-1.0, 4.7.x-1.0, 4.7.x-2.0, apply the same update to use the check plain function for parameters.
As a temporary workaround, consider restricting access to unspecified parameters until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drupal