First published: Tue Feb 23 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ilya Ivanchenko Itweak Upload | =6.x-1.0 | |
Ilya Ivanchenko Itweak Upload | =6.x-1.1 | |
Ilya Ivanchenko Itweak Upload | =6.x-1.x-dev | |
Ilya Ivanchenko Itweak Upload | =6.x-2.0-rc1 | |
Ilya Ivanchenko Itweak Upload | =6.x-2.1 | |
Ilya Ivanchenko Itweak Upload | =6.x-2.1-rc2 | |
Ilya Ivanchenko Itweak Upload | =6.x-2.2 | |
Ilya Ivanchenko Itweak Upload | =6.x-2.x-dev | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0697 is classified as a moderate severity cross-site scripting vulnerability.
To fix CVE-2010-0697, upgrade the iTweak Upload module to version 6.x-1.2 or 6.x-2.3 or later.
CVE-2010-0697 affects remote authenticated users with create content and upload file permissions on Drupal installations using vulnerable versions of the iTweak Upload module.
The affected versions of iTweak Upload include 6.x-1.0, 6.x-1.1, 6.x-1.x-dev, 6.x-2.0-rc1, 6.x-2.1, 6.x-2.1-rc2, and 6.x-2.2.
Attackers can exploit CVE-2010-0697 to inject arbitrary web script or HTML via the file name of an uploaded file.