CVE-2010-1584: XSS
Published May 18, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.
Affected Software
26 affected components
Steven Jones Context<=6.x-2.0
Steven Jones Context=6.x-2.0-alpha1
Steven Jones Context=6.x-2.0-alpha2
Steven Jones Context=6.x-2.0-beta1
Steven Jones Context=6.x-2.0-beta2
Steven Jones Context=6.x-2.0-beta3
Steven Jones Context=6.x-2.0-beta4
Steven Jones Context=6.x-2.0-beta5
Steven Jones Context=6.x-2.0-beta6
Steven Jones Context=6.x-2.0-beta7
Steven Jones Context=6.x-2.0-rc1
Steven Jones Context=6.x-2.0-rc2
Drupal Drupal
All of the following
Any of the following
Steven Jones Context<=6.x-2.0
Steven Jones Context=6.x-2.0-alpha1
Steven Jones Context=6.x-2.0-alpha2
Steven Jones Context=6.x-2.0-beta1
Steven Jones Context=6.x-2.0-beta2
Steven Jones Context=6.x-2.0-beta3
Steven Jones Context=6.x-2.0-beta4
Steven Jones Context=6.x-2.0-beta5
Steven Jones Context=6.x-2.0-beta6
Steven Jones Context=6.x-2.0-beta7
Steven Jones Context=6.x-2.0-rc1
Steven Jones Context=6.x-2.0-rc2
Drupal Drupal
Remediation
Patch Available
Event History
May 18, 2010
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
Description
May 19, 2010
Data Sourced
12:08 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·12:08 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1584?
CVE-2010-1584 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2010-1584?
To fix CVE-2010-1584, update the Context module to version 6.x-2.0-rc4 or later.
3
Who is affected by CVE-2010-1584?
CVE-2010-1584 affects remote authenticated users with Administer Blocks privileges on affected versions of the Context module.
4
What types of attacks can CVE-2010-1584 enable?
CVE-2010-1584 can enable attackers to inject arbitrary web script or HTML into Drupal sites.
5
Which versions of the Context module are vulnerable to CVE-2010-1584?
Versions of the Context module earlier than 6.x-2.0-rc4 are vulnerable to CVE-2010-1584.