Lucene search

K
cve[email protected]CVE-2007-0534
HistoryJan 26, 2007 - 1:28 a.m.

CVE-2007-0534

2007-01-2601:28:00
web.nvd.nist.gov
23
cve-2007-0534
cross-site scripting
xss
drupal
vulnerabilities
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.3%

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain “fields on project nodes” or (b) “certain project-specific settings regarding issue tracking.”

Affected configurations

NVD
Node
drupalprojectRange5
OR
drupalprojectMatch4.6.0
OR
drupalproject_issue_tracking_moduleRange5
OR
drupalproject_issue_tracking_moduleMatch4.7.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.3%

Related for CVE-2007-0534