Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.57104
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: drupal
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: drupal

CVE-2006-2833
Cross-site scripting (XSS) vulnerability in the taxonomy module in
Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web
script or HTML via inputs that are not properly validated when the
page title is output, possibly involving the $names variable.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-2833
BugTraq ID: 18245
http://www.securityfocus.com/bid/18245
Bugtraq: 20060602 [DRUPAL-SA-2006-008] Drupal 4.6.8 / 4.7.2 fixes XSS issue (Google Search)
http://www.securityfocus.com/archive/1/435793/100/0/threaded
Debian Security Information: DSA-1125 (Google Search)
http://www.debian.org/security/2006/dsa-1125
http://secunia.com/advisories/20412
http://secunia.com/advisories/21244
http://securityreason.com/securityalert/1041
http://www.vupen.com/english/advisories/2006/2112
XForce ISS Database: drupal-taxonomy-xss(26893)
https://exchange.xforce.ibmcloud.com/vulnerabilities/26893
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.