CVE-2010-0697: XSS
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0697?
CVE-2010-0697 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2010-0697?
To fix CVE-2010-0697, upgrade the iTweak Upload module to version 6.x-1.2 or 6.x-2.3 or later.
Who is affected by CVE-2010-0697?
CVE-2010-0697 affects remote authenticated users with create content and upload file permissions on Drupal installations using vulnerable versions of the iTweak Upload module.
What versions of iTweak Upload are affected by CVE-2010-0697?
The affected versions of iTweak Upload include 6.x-1.0, 6.x-1.1, 6.x-1.x-dev, 6.x-2.0-rc1, 6.x-2.1, 6.x-2.1-rc2, and 6.x-2.2.
What can attackers do exploiting CVE-2010-0697?
Attackers can exploit CVE-2010-0697 to inject arbitrary web script or HTML via the file name of an uploaded file.