CVE-2009-2076: XSS
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is only exploitable by users with administer views permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2076?
CVE-2009-2076 is classified as a medium severity vulnerability due to its potential for exploitation by authenticated users.
How do I fix CVE-2009-2076?
To fix CVE-2009-2076, upgrade the Views module to version 6.x-2.6 or later.
Who is affected by CVE-2009-2076?
CVE-2009-2076 affects users of Drupal Views versions 6.x-2.0 to 6.x-2.5.
What type of vulnerability is CVE-2009-2076?
CVE-2009-2076 is a cross-site scripting (XSS) vulnerability.
Can CVE-2009-2076 be exploited remotely?
Yes, CVE-2009-2076 can be exploited by remote authenticated users to inject arbitrary web scripts.