CVE-2006-4355: XSS
Published Aug 26, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected components
Drupal Drupal Easylinks Module=4.7
Drupal Drupal Easylinks Module=4.7.0
Drupal Drupal Easylinks Module=4.7.1
Drupal Drupal Easylinks Module=4.7.2
Remediation
Patch Available
Patch Available
Event History
Aug 26, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4355?
CVE-2006-4355 is classified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2006-4355?
To fix CVE-2006-4355, upgrade the Drupal Easylinks Module to version 1.5.2.1 or later.
3
What systems are affected by CVE-2006-4355?
CVE-2006-4355 affects Drupal Easylinks Module versions 4.7.0 through 4.7.2.
4
What type of vulnerability is CVE-2006-4355?
CVE-2006-4355 is a cross-site scripting (XSS) vulnerability allowing for injection of arbitrary web scripts or HTML.
5
Who can exploit CVE-2006-4355?
Remote attackers can exploit CVE-2006-4355 if they have access to the vulnerable Drupal Easylinks Module.