4.3

CVE-2015-6665

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Fedoraproject ≫ Fedora Version 23
Drupal ≫ Drupal Version 7.0
Drupal ≫ Drupal Version 7.0 Update alpha1
Drupal ≫ Drupal Version 7.0 Update alpha2
Drupal ≫ Drupal Version 7.0 Update alpha3
Drupal ≫ Drupal Version 7.0 Update alpha4
Drupal ≫ Drupal Version 7.0 Update alpha5
Drupal ≫ Drupal Version 7.0 Update alpha6
Drupal ≫ Drupal Version 7.0 Update alpha7
Drupal ≫ Drupal Version 7.0 Update beta1
Drupal ≫ Drupal Version 7.0 Update beta2
Drupal ≫ Drupal Version 7.0 Update beta3
Drupal ≫ Drupal Version 7.0 Update dev
Drupal ≫ Drupal Version 7.0 Update rc1
Drupal ≫ Drupal Version 7.0 Update rc2
Drupal ≫ Drupal Version 7.0 Update rc3
Drupal ≫ Drupal Version 7.0 Update rc4
Drupal ≫ Drupal Version 7.1
Drupal ≫ Drupal Version 7.2
Drupal ≫ Drupal Version 7.3
Drupal ≫ Drupal Version 7.4
Drupal ≫ Drupal Version 7.5
Drupal ≫ Drupal Version 7.6
Drupal ≫ Drupal Version 7.7
Drupal ≫ Drupal Version 7.8
Drupal ≫ Drupal Version 7.9
Drupal ≫ Drupal Version 7.10
Drupal ≫ Drupal Version 7.11
Drupal ≫ Drupal Version 7.12
Drupal ≫ Drupal Version 7.13
Drupal ≫ Drupal Version 7.14
Drupal ≫ Drupal Version 7.15
Drupal ≫ Drupal Version 7.16
Drupal ≫ Drupal Version 7.17
Drupal ≫ Drupal Version 7.18
Drupal ≫ Drupal Version 7.19
Drupal ≫ Drupal Version 7.20
Drupal ≫ Drupal Version 7.21
Drupal ≫ Drupal Version 7.22
Drupal ≫ Drupal Version 7.23
Drupal ≫ Drupal Version 7.24
Drupal ≫ Drupal Version 7.25
Drupal ≫ Drupal Version 7.26
Drupal ≫ Drupal Version 7.27
Drupal ≫ Drupal Version 7.28
Drupal ≫ Drupal Version 7.29
Drupal ≫ Drupal Version 7.30
Drupal ≫ Drupal Version 7.33
Drupal ≫ Drupal Version 7.34
Drupal ≫ Drupal Version 7.35
Drupal ≫ Drupal Version 7.36
Drupal ≫ Drupal Version 7.37
Drupal ≫ Drupal Version 7.38
Drupal ≫ Drupal Version 7.x-dev
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update alpha1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update alpha2 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update alpha3 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update beta1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update beta2 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update beta3 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update beta4 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.0 Update rc1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.1 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.2 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.3 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.4 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.5 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.6 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.7 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.8 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.9 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.11 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.12 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.13 SwPlatform drupal
Chaos Tool Suite Project ≫ Ctools Version 6.x-1.x Update dev SwPlatform drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.69% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.html
http://www.debian.org/security/2015/dsa-3346
http://www.securitytracker.com/id/1033358
https://www.drupal.org/SA-CORE-2015-003
Patch
Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.html
http://www.securityfocus.com/bid/76431
https://www.drupal.org/node/2554133
Patch
https://www.drupal.org/node/2554145
Patch
Vendor Advisory