First published: Tue Jun 16 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is only exploitable by users with administer views permissions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Views | =6.x-2.0 | |
Drupal Views | =6.x-2.1 | |
Drupal Views | =6.x-2.2 | |
Drupal Views | =6.x-2.3 | |
Drupal Views | =6.x-2.4 | |
Drupal Views | =6.x-2.5 | |
Drupal Drupal | ||
All of | ||
Any of | ||
Drupal Views | =6.x-2.0 | |
Drupal Views | =6.x-2.1 | |
Drupal Views | =6.x-2.2 | |
Drupal Views | =6.x-2.3 | |
Drupal Views | =6.x-2.4 | |
Drupal Views | =6.x-2.5 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.