Cross-Site Scripting Vulnerability in Drupal Views Module
CVE-2009-2076
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability exists in the Views module for Drupal, affecting versions prior to 6.x-2.6. This vulnerability allows remote authenticated users to inject arbitrary web scripts or HTML into the application through exposed filters in the Views UI administrative interface and the view name parameter within the define custom views feature. The second vector of exploitation can only be executed by users with administrator-level permissions for the Views feature.
References
Timeline
Vulnerability Reserved
Vulnerability published