Cross-Site Scripting Vulnerability in EveryBlog for Drupal by EveryBlog
CVE-2008-6135

Currently unrated

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
14 February 2009

Summary

The vulnerability in EveryBlog versions 5.x and 6.x enables remote attackers to exploit cross-site scripting (XSS) flaws, allowing them to inject arbitrary web scripts or HTML. This poses a significant risk to users, as malicious scripts may be executed within the context of the user's browser, potentially leading to unauthorized actions or data exposure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.