Vulnerabilities > CVE-2006-4002 - Cross-Site Scripting vulnerability in Drupal User.Module
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information. This vulnerability is addressed in the following product releases: Drupal, Drupal, 4.6.9 Drupal, Drupal, 4.7.3
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 12 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-1147.NASL |
description | Ayman Hourieh discovered that Drupal, a dynamic website platform, performs insufficient input sanitising in the user module, which might lead to cross-site scripting. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22689 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22689 |
title | Debian DSA-1147-1 : drupal - missing input sanitising |