First published: Tue Jun 06 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =4.6.0 | |
Drupal Drupal | =4.6 | |
Drupal Drupal | =4.6.5 | |
Drupal Drupal | =4.6.2 | |
Drupal Drupal | =4.6.3 | |
Drupal Drupal | =4.6.4 | |
Drupal Drupal | =4.7.0 | |
Drupal Drupal | =4.6.7 | |
Drupal Drupal | =4.6.1 | |
Drupal Drupal | =4.7.1 | |
Drupal Drupal | =4.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2832 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-2832, you should upgrade to Drupal versions 4.6.8 or 4.7.2 or later.
Affected versions include Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2.
CVE-2006-2832 is a cross-site scripting (XSS) vulnerability.
Yes, attackers can exploit CVE-2006-2832 without authentication by uploading malicious filenames.