CVE-2006-4120: XSS
Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4120?
CVE-2006-4120 is classified as a medium severity vulnerability due to its potential to allow arbitrary web script or HTML injection.
How do I fix CVE-2006-4120?
To fix CVE-2006-4120, upgrade the affected Recipe module to version 1.54 or later for Drupal sites.
Which versions of Drupal are affected by CVE-2006-4120?
CVE-2006-4120 affects Drupal versions 4.6 and earlier, including specific versions such as 4.0, 4.5.x, and Recipe module versions up to 1.53.
What type of vulnerability is CVE-2006-4120?
CVE-2006-4120 is a Cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2006-4120?
Remote attackers can exploit CVE-2006-4120 to inject arbitrary web scripts or HTML into the vulnerable application.