2.1
CVE-2010-1958
- EPSS 0.27%
- Veröffentlicht 21.06.2010 19:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Quicksketch ≫ Filefield Version5.x-1.x-dev
Quicksketch ≫ Filefield Version5.x-2.0
Quicksketch ≫ Filefield Version5.x-2.1
Quicksketch ≫ Filefield Version5.x-2.2
Quicksketch ≫ Filefield Version5.x-2.3
Quicksketch ≫ Filefield Version5.x-2.3 Updaterc2
Quicksketch ≫ Filefield Version5.x-2.3 Updaterc3
Quicksketch ≫ Filefield Version5.x-2.3 Updaterc4
Quicksketch ≫ Filefield Version5.x-2.4
Quicksketch ≫ Filefield Version5.x-2.x-dev
Quicksketch ≫ Filefield Version6.x-1.0 Updatealpha1
Quicksketch ≫ Filefield Version6.x-1.0 Updatealpha2
Quicksketch ≫ Filefield Version6.x-1.0 Updatealpha3
Quicksketch ≫ Filefield Version6.x-1.0 Updatebeta1
Quicksketch ≫ Filefield Version6.x-1.0 Updatebeta2
Quicksketch ≫ Filefield Version6.x-1.0 Updatebeta3
Quicksketch ≫ Filefield Version6.x-3.0
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha1
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha2
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha3
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha4
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha5
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha6
Quicksketch ≫ Filefield Version6.x-3.0 Updatealpha7
Quicksketch ≫ Filefield Version6.x-3.0 Updatebeta1
Quicksketch ≫ Filefield Version6.x-3.0 Updatebeta2
Quicksketch ≫ Filefield Version6.x-3.0 Updatebeta3
Quicksketch ≫ Filefield Version6.x-3.0 Updaterc1
Quicksketch ≫ Filefield Version6.x-3.1
Quicksketch ≫ Filefield Version6.x-3.2
Quicksketch ≫ Filefield Version6.x-3.3
Quicksketch ≫ Filefield Version6.x-3.5
Quicksketch ≫ Filefield Version6.x-3.x-dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.502 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.