First published: Mon Aug 14 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | <=4.6 | |
Drupal Drupal | =4.5.4 | |
Drupal Drupal | =4.5.2 | |
Drupal Recipe Module | <=1.53 | |
Drupal Drupal | =4.0 | |
Drupal Drupal | =4.5.7 | |
Drupal Drupal | =4.4.1 | |
Drupal Drupal | =4.5.1 | |
Drupal Drupal | =4.4.2 | |
Drupal Drupal | =4.5.5 | |
Drupal Drupal | =4.5 | |
Drupal Drupal | =4.5.3 | |
Drupal Drupal | =4.4.0 | |
Drupal Drupal | =4.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4120 is classified as a medium severity vulnerability due to its potential to allow arbitrary web script or HTML injection.
To fix CVE-2006-4120, upgrade the affected Recipe module to version 1.54 or later for Drupal sites.
CVE-2006-4120 affects Drupal versions 4.6 and earlier, including specific versions such as 4.0, 4.5.x, and Recipe module versions up to 1.53.
CVE-2006-4120 is a Cross-site scripting (XSS) vulnerability.
Remote attackers can exploit CVE-2006-4120 to inject arbitrary web scripts or HTML into the vulnerable application.