3.5

CVE-2009-1942

Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drupal ≫ Quiz Version 5.x
Drupal ≫ Quiz Version 6.x-2.0
Drupal ≫ Quiz Version 6.x-2.0 Update alpha1
Drupal ≫ Quiz Version 6.x-2.0 Update alpha2
Drupal ≫ Quiz Version 6.x-2.0 Update beta1
Drupal ≫ Quiz Version 6.x-2.0 Update rc1
Drupal ≫ Quiz Version 6.x-2.0 Update rc2
Drupal ≫ Quiz Version 6.x-2.1
Drupal ≫ Quiz Version 6.x-2.x Update dev
Drupal ≫ Quiz Version 6.x-3.0
Drupal ≫ Quiz Version 6.x-3.0 Update alpha1
Drupal ≫ Quiz Version 6.x-3.0 Update alpha2
Drupal ≫ Quiz Version 6.x-3.0 Update beta1
Drupal ≫ Quiz Version 6.x-3.x Update dev
Drupal ≫ Quiz Version 6.x-3.x Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.581
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://drupal.org/node/481270
Patch
http://drupal.org/node/481274
Patch
Vendor Advisory
http://drupal.org/node/481308
http://osvdb.org/54880
Patch
http://secunia.com/advisories/35345
Vendor Advisory
http://www.securityfocus.com/bid/35199
Patch