Vulnerability Name: | CVE-2006-4947 (CCN-29063) | ||||||||
Assigned: | 2006-09-20 | ||||||||
Published: | 2006-09-20 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "lack of validation on output." Drupal core is not affected. If you do not use the Search Keywords module there is nothing you need to do. This issue may allow an attacker to gain administrative privileges, provided that certain conditions are met. This vulnerability is addressed in the following module update: Drupal, Search Keyword Module, 1.15 (patch 2006/09/15) | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-4947 Source: CCN Type: DRUPAL-SA-2006-022 Search Keywords cross site scripting vulnerability Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/85050 Source: CCN Type: SA22021 Drupal Search Keywords Module Script Insertion Source: SECUNIA Type: Patch, Vendor Advisory 22021 Source: CCN Type: OSVDB ID: 29030 Drupal Search Keywords Module Unspecified XSS Source: BID Type: Patch 20126 Source: CCN Type: BID-20126 Drupal Search Keywords Module HTML Injection Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-3715 Source: XF Type: UNKNOWN searchkeywords-parameters-xss(29063) Source: XF Type: UNKNOWN searchkeywords-parameters-xss(29063) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |