CVE-2010-2125: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Rotor Banner module 5.x before 5.x-1.8 and 6.x before 6.x-2.5 for Drupal allow remote authenticated users, with "create rotor item" or "edit any rotor item" privileges, to inject arbitrary web script or HTML via the (1) srs, (2) title, or (3) alt image attribute.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2125?
The severity of CVE-2010-2125 is classified as medium.
How do I fix CVE-2010-2125?
To fix CVE-2010-2125, upgrade the Rotor module to version 5.x-1.8 or 6.x-2.5 or later.
Who is affected by CVE-2010-2125?
CVE-2010-2125 affects users of the Rotor Banner module versions prior to 5.x-1.8 and 6.x-2.5 in Drupal.
What types of attacks are possible with CVE-2010-2125?
CVE-2010-2125 allows remote authenticated users to conduct cross-site scripting (XSS) attacks.
What versions of the Rotor module are vulnerable to CVE-2010-2125?
Versions 5.x before 5.x-1.8 and 6.x before 6.x-2.5 of the Rotor module are vulnerable to CVE-2010-2125.