PT-2006-7248 · Drupal · Drupal

Derek Wright

+1

·

Published

2006-12-20

·

Updated

2011-03-08

·

CVE-2006-6646

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal Project Issue Tracking versions 4.7.x-1.0 through 4.7.x-2.0 Drupal Project versions 4.6.x-1.0, 4.7.x-1.0, 4.7.x-2.0
Description The issue allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. This is possible because the check plain function is not used.
Recommendations For Drupal Project Issue Tracking versions 4.7.x-1.0 through 4.7.x-2.0, update to ensure the check plain function is utilized for all parameters. For Drupal Project versions 4.6.x-1.0, 4.7.x-1.0, 4.7.x-2.0, apply the same update to use the check plain function for parameters. As a temporary workaround, consider restricting access to unspecified parameters until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6646

Affected Products

Drupal