4.3

CVE-2015-6665

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.

Data is provided by the National Vulnerability Database (NVD)
FedoraprojectFedora Version21
FedoraprojectFedora Version22
FedoraprojectFedora Version23
DrupalDrupal Version7.0
DrupalDrupal Version7.0 Updatealpha1
DrupalDrupal Version7.0 Updatealpha2
DrupalDrupal Version7.0 Updatealpha3
DrupalDrupal Version7.0 Updatealpha4
DrupalDrupal Version7.0 Updatealpha5
DrupalDrupal Version7.0 Updatealpha6
DrupalDrupal Version7.0 Updatealpha7
DrupalDrupal Version7.0 Updatebeta1
DrupalDrupal Version7.0 Updatebeta2
DrupalDrupal Version7.0 Updatebeta3
DrupalDrupal Version7.0 Updatedev
DrupalDrupal Version7.0 Updaterc1
DrupalDrupal Version7.0 Updaterc2
DrupalDrupal Version7.0 Updaterc3
DrupalDrupal Version7.0 Updaterc4
DrupalDrupal Version7.1
DrupalDrupal Version7.2
DrupalDrupal Version7.3
DrupalDrupal Version7.4
DrupalDrupal Version7.5
DrupalDrupal Version7.6
DrupalDrupal Version7.7
DrupalDrupal Version7.8
DrupalDrupal Version7.9
DrupalDrupal Version7.10
DrupalDrupal Version7.11
DrupalDrupal Version7.12
DrupalDrupal Version7.13
DrupalDrupal Version7.14
DrupalDrupal Version7.15
DrupalDrupal Version7.16
DrupalDrupal Version7.17
DrupalDrupal Version7.18
DrupalDrupal Version7.19
DrupalDrupal Version7.20
DrupalDrupal Version7.21
DrupalDrupal Version7.22
DrupalDrupal Version7.23
DrupalDrupal Version7.24
DrupalDrupal Version7.25
DrupalDrupal Version7.26
DrupalDrupal Version7.27
DrupalDrupal Version7.28
DrupalDrupal Version7.29
DrupalDrupal Version7.30
DrupalDrupal Version7.33
DrupalDrupal Version7.34
DrupalDrupal Version7.35
DrupalDrupal Version7.36
DrupalDrupal Version7.37
DrupalDrupal Version7.38
DrupalDrupal Version7.x-dev
Chaos Tool Suite ProjectCtools Version6.x-1.0 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatealpha1 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatealpha2 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatealpha3 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatebeta1 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatebeta2 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatebeta3 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updatebeta4 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.0 Updaterc1 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.1 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.2 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.3 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.4 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.5 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.6 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.7 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.8 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.9 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.11 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.12 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.13 SwPlatformdrupal
Chaos Tool Suite ProjectCtools Version6.x-1.x Updatedev SwPlatformdrupal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.82% 0.737
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.