CVE-2010-2250: XSS
Published Nov 7, 2019
·Updated
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Affected Software
3 affected components
debian/drupal6
Drupal Drupal>=6.0<6.16
Drupal Drupal>=5.0<5.22
Remediation
Patch Available
Event History
Nov 7, 2019
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2010-2250?
CVE-2010-2250 is a vulnerability in Drupal 5.x and 6.x before 6.16 that allows an attacker to perform a cross-site scripting attack.
2
How does CVE-2010-2250 affect Drupal?
CVE-2010-2250 affects Drupal versions 5.x and 6.x before 6.16.
3
What is the severity of CVE-2010-2250?
CVE-2010-2250 has a severity rating of medium with a CVSS score of 6.1.
4
How can an attacker exploit CVE-2010-2250?
An attacker can exploit CVE-2010-2250 by crafting a URL and performing a cross-site scripting attack.
5
Is there a fix for CVE-2010-2250?
Yes, the fix for CVE-2010-2250 is to upgrade to Drupal version 6.16 or later.