2.1
CVE-2012-1660
- EPSS 1.28%
- Veröffentlicht 18.09.2012 20:55:02
- Zuletzt bearbeitet 16.06.2026 23:40:02
- Erkennungen
Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nathan Haug ≫ Webform Version 6.x-3.0
Nathan Haug ≫ Webform Version 6.x-3.0 Update beta1
Nathan Haug ≫ Webform Version 6.x-3.0 Update beta2
Nathan Haug ≫ Webform Version 6.x-3.0 Update beta3
Nathan Haug ≫ Webform Version 6.x-3.0 Update beta4
Nathan Haug ≫ Webform Version 6.x-3.0 Update beta5
Nathan Haug ≫ Webform Version 6.x-3.0 Update beta6
Nathan Haug ≫ Webform Version 6.x-3.1
Nathan Haug ≫ Webform Version 6.x-3.2
Nathan Haug ≫ Webform Version 6.x-3.3
Nathan Haug ≫ Webform Version 6.x-3.4
Nathan Haug ≫ Webform Version 6.x-3.5
Nathan Haug ≫ Webform Version 6.x-3.6
Nathan Haug ≫ Webform Version 6.x-3.7
Nathan Haug ≫ Webform Version 6.x-3.8
Nathan Haug ≫ Webform Version 6.x-3.9
Nathan Haug ≫ Webform Version 6.x-3.10
Nathan Haug ≫ Webform Version 6.x-3.11
Nathan Haug ≫ Webform Version 6.x-3.12
Nathan Haug ≫ Webform Version 6.x-3.13
Nathan Haug ≫ Webform Version 6.x-3.14
Nathan Haug ≫ Webform Version 6.x-3.15
Nathan Haug ≫ Webform Version 6.x-3.16
Nathan Haug ≫ Webform Version 6.x-3.x Update dev
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta2
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta3
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta4
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta5
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta6
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta7
Nathan Haug ≫ Webform Version 7.x-3.0 Update beta8
Nathan Haug ≫ Webform Version 7.x-3.3 Update beta1
Nathan Haug ≫ Webform Version 7.x-3.4 Update beta1
Nathan Haug ≫ Webform Version 7.x-3.6
Nathan Haug ≫ Webform Version 7.x-3.7
Nathan Haug ≫ Webform Version 7.x-3.8
Nathan Haug ≫ Webform Version 7.x-3.9
Nathan Haug ≫ Webform Version 7.x-3.10
Nathan Haug ≫ Webform Version 7.x-3.11
Nathan Haug ≫ Webform Version 7.x-3.12
Nathan Haug ≫ Webform Version 7.x-3.13
Nathan Haug ≫ Webform Version 7.x-3.15
Nathan Haug ≫ Webform Version 7.x-3.16
Nathan Haug ≫ Webform Version 7.x-3.x Update dev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.28% | 0.662 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://www.openwall.com/lists/oss-security/2012/04/07/1
http://drupal.org/node/1472178
http://drupal.org/node/1472180
http://drupal.org/node/1472214
http://drupalcode.org/project/webform.git/commit/90af819
http://drupalcode.org/project/webform.git/commit/917fa91
http://secunia.com/advisories/48310
http://www.osvdb.org/79852
http://www.securityfocus.com/bid/52345
https://exchange.xforce.ibmcloud.com/vulnerabilities/73779