Lucene search

K
cve[email protected]CVE-2010-1958
HistoryJun 21, 2010 - 7:30 p.m.

CVE-2010-1958

2010-06-2119:30:01
CWE-79
web.nvd.nist.gov
22
cve-2010-1958
xss
filefield module
drupal
nvd

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.6%

Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and ‘Path to File’ or ‘URL to File’ display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).

Affected configurations

NVD
Node
drupaldrupal
AND
quicksketchfilefieldMatch5.x-1.x-dev
OR
quicksketchfilefieldMatch5.x-2.0
OR
quicksketchfilefieldMatch5.x-2.1
OR
quicksketchfilefieldMatch5.x-2.2
OR
quicksketchfilefieldMatch5.x-2.3
OR
quicksketchfilefieldMatch5.x-2.3rc2
OR
quicksketchfilefieldMatch5.x-2.3rc3
OR
quicksketchfilefieldMatch5.x-2.3rc4
OR
quicksketchfilefieldMatch5.x-2.4
OR
quicksketchfilefieldMatch5.x-2.x-dev
OR
quicksketchfilefieldMatch6.x-1.0alpha1
OR
quicksketchfilefieldMatch6.x-1.0alpha2
OR
quicksketchfilefieldMatch6.x-1.0alpha3
OR
quicksketchfilefieldMatch6.x-1.0beta1
OR
quicksketchfilefieldMatch6.x-1.0beta2
OR
quicksketchfilefieldMatch6.x-1.0beta3
OR
quicksketchfilefieldMatch6.x-3.0
OR
quicksketchfilefieldMatch6.x-3.0alpha1
OR
quicksketchfilefieldMatch6.x-3.0alpha2
OR
quicksketchfilefieldMatch6.x-3.0alpha3
OR
quicksketchfilefieldMatch6.x-3.0alpha4
OR
quicksketchfilefieldMatch6.x-3.0alpha5
OR
quicksketchfilefieldMatch6.x-3.0alpha6
OR
quicksketchfilefieldMatch6.x-3.0alpha7
OR
quicksketchfilefieldMatch6.x-3.0beta1
OR
quicksketchfilefieldMatch6.x-3.0beta2
OR
quicksketchfilefieldMatch6.x-3.0beta3
OR
quicksketchfilefieldMatch6.x-3.0rc1
OR
quicksketchfilefieldMatch6.x-3.1
OR
quicksketchfilefieldMatch6.x-3.2
OR
quicksketchfilefieldMatch6.x-3.3
OR
quicksketchfilefieldMatch6.x-3.5
OR
quicksketchfilefieldMatch6.x-3.x-dev

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.6%

Related for CVE-2010-1958