Vulnerabilities > CVE-2006-4002 - Unspecified vulnerability in Drupal
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN drupal
nessus
Summary
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 12 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1147.NASL |
description | Ayman Hourieh discovered that Drupal, a dynamic website platform, performs insufficient input sanitising in the user module, which might lead to cross-site scripting. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22689 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22689 |
title | Debian DSA-1147-1 : drupal - missing input sanitising |
References
- http://drupal.org/node/76748
- http://drupal.org/node/76748
- http://secunia.com/advisories/21332
- http://secunia.com/advisories/21332
- http://secunia.com/advisories/21503
- http://secunia.com/advisories/21503
- http://www.debian.org/security/2006/dsa-1147
- http://www.debian.org/security/2006/dsa-1147
- http://www.securityfocus.com/bid/19325
- http://www.securityfocus.com/bid/19325
- http://www.vupen.com/english/advisories/2006/3138
- http://www.vupen.com/english/advisories/2006/3138
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28184
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28184