CVE-2010-2000: XSS
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1358.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2000?
The severity of CVE-2010-2000 is considered medium due to its exploitation potential allowing XSS attacks.
How do I fix CVE-2010-2000?
To fix CVE-2010-2000, update the Bibliography module to a secure version, specifically 5.x-1.18 or 6.x-1.10 and later.
Who is affected by CVE-2010-2000?
CVE-2010-2000 affects users of the Bibliography module on Drupal versions 5.x (up to 5.x-1.17) and 6.x (up to 6.x-1.9).
What type of vulnerability is CVE-2010-2000?
CVE-2010-2000 is classified as a cross-site scripting (XSS) vulnerability.
Can anonymous users exploit CVE-2010-2000?
No, only authenticated users with 'administer biblio' privileges can exploit CVE-2010-2000.