CVE-2005-0682: XSS
Published Mar 7, 2005
·Updated
Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
Affected Software
5 affected components
Drupal Drupal=4.5.0
Drupal Drupal=4.4.1
Drupal Drupal=4.5.1
Drupal Drupal=4.4.2
Drupal Drupal=4.4.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 7, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0682?
CVE-2005-0682 is classified as a moderate severity vulnerability due to its potential to allow arbitrary script injection.
2
How do I fix CVE-2005-0682?
To fix CVE-2005-0682, you should upgrade to Drupal version 4.5.2 or later, which includes the security patch.
3
Which versions of Drupal are affected by CVE-2005-0682?
CVE-2005-0682 affects Drupal versions 4.4.0 through 4.5.1.
4
What kind of attacks can be executed through CVE-2005-0682?
Exploiting CVE-2005-0682 can lead to cross-site scripting (XSS) attacks that allow attackers to inject malicious web scripts.
5
Is there a patch available for CVE-2005-0682?
Yes, a patch for CVE-2005-0682 is included in the update to Drupal version 4.5.2.