First published: Tue Jun 16 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is only exploitable by users with administer views permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Drupal Views | =6.x-2.0 | |
Drupal Views | =6.x-2.1 | |
Drupal Views | =6.x-2.2 | |
Drupal Views | =6.x-2.3 | |
Drupal Views | =6.x-2.4 | |
Drupal Views | =6.x-2.5 | |
Drupal | ||
Drupal Views | =6.x-2.0 | |
Drupal Views | =6.x-2.1 | |
Drupal Views | =6.x-2.2 | |
Drupal Views | =6.x-2.3 | |
Drupal Views | =6.x-2.4 | |
Drupal Views | =6.x-2.5 | |
Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2076 is classified as a medium severity vulnerability due to its potential for exploitation by authenticated users.
To fix CVE-2009-2076, upgrade the Views module to version 6.x-2.6 or later.
CVE-2009-2076 affects users of Drupal Views versions 6.x-2.0 to 6.x-2.5.
CVE-2009-2076 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2009-2076 can be exploited by remote authenticated users to inject arbitrary web scripts.