CVE-2006-4002: XSS
Published Aug 7, 2006
·Updated
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.
Affected Software
12 affected components
Drupal Drupal=4.6.0
Drupal Drupal=4.6.5
Drupal Drupal=4.7.2
Drupal Drupal=4.6.2
Drupal Drupal=4.6.8
Drupal Drupal=4.6.3
Drupal Drupal=4.6.4
Drupal Drupal=4.7.0
Drupal Drupal=4.6.7
Drupal Drupal=4.6.1
Drupal Drupal=4.7.1
Drupal Drupal=4.6.6
Remediation
Patch Available
Patch Available
Event History
Aug 7, 2006
CVE Published
07:04 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4002?
CVE-2006-4002 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2006-4002?
To fix CVE-2006-4002, upgrade your Drupal installation to version 4.6.9 or 4.7.3 or later.
3
Which versions of Drupal are affected by CVE-2006-4002?
CVE-2006-4002 affects Drupal versions 4.6.0 through 4.6.8 and 4.7.0 through 4.7.2.
4
What is the nature of the attack for CVE-2006-4002?
CVE-2006-4002 allows remote attackers to inject arbitrary web scripts or HTML via the msg parameter.
5
When was CVE-2006-4002 disclosed?
CVE-2006-4002 was publicly disclosed in July 2006.