6.8
CVE-2007-1028
- EPSS 1.18%
- Veröffentlicht 21.02.2007 11:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTML entities and the IMG element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Barry Jaspan ≫ Image Pager Version4.7
Barry Jaspan ≫ Image Pager Version5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.18% | 0.637 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://drupal.org/node/119293
http://osvdb.org/35151
http://www.securityfocus.com/bid/22586
http://www.vupen.com/english/advisories/2007/0636
https://exchange.xforce.ibmcloud.com/vulnerabilities/32539