CVE-2006-4109: XSS
Cross-site scripting (XSS) vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4109?
CVE-2006-4109 is classified as a cross-site scripting (XSS) vulnerability which can lead to unauthorized script injection.
How do I fix CVE-2006-4109?
To resolve CVE-2006-4109, upgrade the Bibliography module to versions 4.7 revision 1.13.2.5 or newer, or 4.6 revision 1.1.1.1.4.11 or newer.
What software is affected by CVE-2006-4109?
CVE-2006-4109 affects Drupal Bibliography module versions prior to 4.6 revision 1.1.1.1.4.11 and 4.7 revision 1.13.2.5.
Can CVE-2006-4109 allow remote attacks?
Yes, CVE-2006-4109 allows remote attackers to inject arbitrary web scripts or HTML into affected Drupal applications.
What are the potential impacts of CVE-2006-4109?
The potential impacts of CVE-2006-4109 include unauthorized script execution and the potential to steal session cookies or perform actions on behalf of users.