CVE-2010-2002: XSS
Published May 20, 2010
·Updated
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list.
Affected Software
11 affected components
Addison Berry Wordfilter=5.x-1.x-dev
Jeff Warrington Wordfilter=5.x-1.0
Drupal Drupal
Jeff Warrington Wordfilter=6.x-1.0
Jeff Warrington Wordfilter=6.x-1.x-dev
All of the following
Any of the following
Addison Berry Wordfilter=5.x-1.x-dev
Jeff Warrington Wordfilter=5.x-1.0
Drupal Drupal
All of the following
Any of the following
Jeff Warrington Wordfilter=6.x-1.0
Jeff Warrington Wordfilter=6.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 20, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2002?
CVE-2010-2002 is classified as a high-severity vulnerability due to its potential for remote exploitation through cross-site scripting.
2
How do I fix CVE-2010-2002?
To resolve CVE-2010-2002, update the Wordfilter module to version 5.x-1.1 or 6.x-1.1 or later.
3
Who is affected by CVE-2010-2002?
CVE-2010-2002 affects Drupal users with the Wordfilter module versions prior to 5.x-1.1 and 6.x-1.1.
4
What type of vulnerability is CVE-2010-2002?
CVE-2010-2002 is a cross-site scripting (XSS) vulnerability.
5
Can unauthenticated users exploit CVE-2010-2002?
No, CVE-2010-2002 requires authenticated users with "administer words filtered" privileges to exploit.