Lucene search

K
cvelistMitreCVELIST:CVE-2006-0070
HistoryJan 04, 2006 - 12:00 a.m.

CVE-2006-0070

2006-01-0400:00:00
mitre
www.cve.org

5.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%

Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when β€œFiltered HTML” is enabled, and since β€œFull HTML” would not filter HTML by design, perhaps this should not be included in CVE

5.7 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

59.8%

Related for CVELIST:CVE-2006-0070