Lucene search

K
cve[email protected]CVE-2006-0070
HistoryJan 04, 2006 - 12:03 a.m.

CVE-2006-0070

2006-01-0400:03:00
web.nvd.nist.gov
23
drupal
xss
cross-site scripting
img tag
encoded
javascript
cve-2006-0070

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.9%

Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when “Filtered HTML” is enabled, and since “Full HTML” would not filter HTML by design, perhaps this should not be included in CVE

Affected configurations

NVD
Node
drupaldrupalMatch4.5.6
OR
drupaldrupalMatch4.6.4

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.9%

Related for CVE-2006-0070