CVE-2006-2260: XSS
Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2260?
CVE-2006-2260 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-2260?
To fix CVE-2006-2260, upgrade your Drupal installation to a version that is not vulnerable to this issue, specifically versions 4.7 or later.
What versions of Drupal are affected by CVE-2006-2260?
CVE-2006-2260 affects Drupal versions 4.5 and 4.6, including all sub-revisions.
Can CVE-2006-2260 be exploited remotely?
Yes, CVE-2006-2260 can be exploited remotely, allowing attackers to inject arbitrary web scripts into affected systems.
What type of vulnerability is CVE-2006-2260?
CVE-2006-2260 is a cross-site scripting (XSS) vulnerability that allows for the injection of malicious scripts.