CVE-2007-0136: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0136?
CVE-2007-0136 is classified as a moderate vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-0136?
To fix CVE-2007-0136, upgrade your Drupal installation to version 4.6.11 or 4.7.5 or later.
Which versions of Drupal are affected by CVE-2007-0136?
CVE-2007-0136 affects Drupal versions prior to 4.6.11 and 4.7 versions prior to 4.7.5.
What types of vulnerabilities does CVE-2007-0136 include?
CVE-2007-0136 includes multiple cross-site scripting (XSS) vulnerabilities.
Can remote attackers exploit CVE-2007-0136?
Yes, remote attackers can exploit CVE-2007-0136 to inject arbitrary web scripts or HTML.