| Vulnerability Name: | CVE-2006-0070 | ||||||||
| Assigned: | 2006-01-03 | ||||||||
| Published: | 2006-01-03 | ||||||||
| Updated: | 2018-10-19 | ||||||||
| Summary: | ** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. Note: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| References: | Source: MITRE Type: CNA CVE-2006-0070 Source: BUGTRAQ Type: Exploit, Vendor Advisory 20060102 Drupal all versiyon xss cehennem.org Source: BUGTRAQ Type: UNKNOWN 20060103 Re: Drupal all versiyon xss cehennem.org | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||