First published: Tue Apr 15 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the insertion filter in the Flickr Drupal module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-alpha allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | ||
Drupalr Flickr | =5.x-0.0-beta | |
Drupalr Flickr | =5.x-1.0 | |
Drupalr Flickr | =5.x-1.1 | |
Drupalr Flickr | =5.x-1.2 | |
Drupalr Flickr | =5.x-1.x-dev | |
Drupalr Flickr | =6.x-1.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1792 is classified as a moderate severity cross-site scripting vulnerability.
To fix CVE-2008-1792, upgrade the Flickr Drupal module to version 5.x-1.3 or 6.x-1.0-alpha or later.
CVE-2008-1792 affects users of the Flickr Drupal module versions prior to 5.x-1.3 and 6.x-1.0-alpha.
CVE-2008-1792 allows remote attackers to inject arbitrary web scripts or HTML into web pages.
CVE-2008-1792 was disclosed in April 2008.