First published: Thu Dec 14 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Help Tip Module | <=4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6531 has a high severity rating due to its ability to allow remote attackers to execute arbitrary scripts.
To fix CVE-2006-6531, upgrade the Help Tip module to version 4.7.x-1.0 or later.
CVE-2006-6531 affects all versions of the Help Tip module prior to 4.7.x-1.0.
CVE-2006-6531 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2006-6531 could potentially allow attackers to obtain administrative access through injected scripts.