First published: Wed Dec 20 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | =5 | |
Drupal | =4.7 | |
=4.7 | ||
=5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6647 is classified as a high severity vulnerability due to the potential for attackers to inject malicious scripts.
To fix CVE-2006-6647, update the MySite module to version 4.7.x-3.3 or 5.x-1.3 or later.
CVE-2006-6647 affects MySite module for Drupal versions 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3.
CVE-2006-6647 is a cross-site scripting (XSS) vulnerability allowing remote code execution via injected scripts.
Yes, CVE-2006-6647 can be exploited remotely by injecting malicious scripts into the Title field when editing a page.