| Vulnerability Name: | CVE-2006-4355 (CCN-28525) | ||||||||
| Assigned: | 2006-08-22 | ||||||||
| Published: | 2006-08-22 | ||||||||
| Updated: | 2017-07-20 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||
| CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2006-4355 Source: CCN Type: DRUPAL-SA-2006-017 Easylinks multiple vulnerabilities Source: CONFIRM Type: Patch http://drupal.org/node/80087 Source: CCN Type: SA21603 Drupal Easylinks Module Script Insertion and SQL Injection Source: SECUNIA Type: Vendor Advisory 21603 Source: CCN Type: OSVDB ID: 28128 Drupal Easylinks Module Unspecified XSS Source: BID Type: Patch 19670 Source: CCN Type: BID-19670 Drupal Easylinks Module Unspecified Cross-Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-3365 Source: XF Type: UNKNOWN easylinks-unspecified-xss(28525) Source: XF Type: UNKNOWN easylinks-unspecified-xss(28525) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||