First published: Fri Aug 25 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Easylinks Module | =4.7 | |
Drupal Easylinks Module | =4.7.0 | |
Drupal Easylinks Module | =4.7.1 | |
Drupal Easylinks Module | =4.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4355 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2006-4355, upgrade the Drupal Easylinks Module to version 1.5.2.1 or later.
CVE-2006-4355 affects Drupal Easylinks Module versions 4.7.0 through 4.7.2.
CVE-2006-4355 is a cross-site scripting (XSS) vulnerability allowing for injection of arbitrary web scripts or HTML.
Remote attackers can exploit CVE-2006-4355 if they have access to the vulnerable Drupal Easylinks Module.