| Vulnerability Name: | CVE-2006-6386 (CCN-30748) | ||||||||
| Assigned: | 2006-12-05 | ||||||||
| Published: | 2006-12-05 | ||||||||
| Updated: | 2017-07-29 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote attackers to inject arbitrary web script or HTML via the motivation field in the CVS application page, which is not passed through check_markup on display. | ||||||||
| CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2006-6386 Source: CCN Type: DRUPAL-SA-2006-028 CVS management/tracker XSS Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/101540 Source: CCN Type: SA23261 Drupal CVS management/tracker Module Cross-Site Scripting Source: SECUNIA Type: Patch, Vendor Advisory 23261 Source: CCN Type: OSVDB ID: 31785 Drupal CVS management/tracker Module motivation Field XSS Source: BID Type: UNKNOWN 21455 Source: CCN Type: BID-21455 Drupal CVS Management/Tracker Motivation Field Cross-Site Scripting Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-4870 Source: XF Type: UNKNOWN drupalcvs-motivation-xss(30748) Source: XF Type: UNKNOWN drupalcvs-motivation-xss(30748) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||