First published: Thu Nov 07 2019(Updated: )
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | >=6.0<6.16 | |
Drupal Drupal | >=5.0<5.22 | |
debian/drupal6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2250 is a vulnerability in Drupal 5.x and 6.x before 6.16 that allows an attacker to perform a cross-site scripting attack.
CVE-2010-2250 affects Drupal versions 5.x and 6.x before 6.16.
CVE-2010-2250 has a severity rating of medium with a CVSS score of 6.1.
An attacker can exploit CVE-2010-2250 by crafting a URL and performing a cross-site scripting attack.
Yes, the fix for CVE-2010-2250 is to upgrade to Drupal version 6.16 or later.