| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.57104 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: drupal |
| Summary: | FreeBSD Ports: drupal |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: drupal CVE-2006-2833 Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable. Solution: Update your system with the appropriate patches or software upgrades. http://drupal.org/node/66767 http://www.vuxml.org/freebsd/6da7344b-128a-11db-b25f-00e00c69a70d.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-2833 Bugtraq: 20060602 [DRUPAL-SA-2006-008] Drupal 4.6.8 / 4.7.2 fixes XSS issue (Google Search) http://www.securityfocus.com/archive/1/archive/1/435793/100/0/threaded Debian Security Information: DSA-1125 (Google Search) http://www.debian.org/security/2006/dsa-1125 BugTraq ID: 18245 http://www.securityfocus.com/bid/18245 http://www.vupen.com/english/advisories/2006/2112 http://secunia.com/advisories/20412 http://secunia.com/advisories/21244 http://securityreason.com/securityalert/1041 XForce ISS Database: drupal-taxonomy-xss(26893) http://xforce.iss.net/xforce/xfdb/26893 |
| Copyright | Copyright (c) 2006 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|