CVE-2010-2001: XSS
Published May 20, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the CiviRegister module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.
Affected Software
4 affected components
Ninjitsuweb Civiregister=6.x-1.0
Drupal Drupal
All of the following
Ninjitsuweb Civiregister=6.x-1.0
Drupal Drupal
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 20, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2001?
CVE-2010-2001 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2010-2001?
You can fix CVE-2010-2001 by updating the CiviRegister module to version 6.x-1.1 or later.
3
Who is affected by CVE-2010-2001?
CVE-2010-2001 affects users of the CiviRegister module version 6.x-1.0 on Drupal.
4
What type of vulnerability is CVE-2010-2001?
CVE-2010-2001 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2010-2001?
Attackers can exploit CVE-2010-2001 to inject arbitrary web scripts or HTML into the website.