Cross-Site Scripting Vulnerability in Drupal Views Module
CVE-2009-2076

Currently unrated

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
16 June 2009

Summary

A cross-site scripting (XSS) vulnerability exists in the Views module for Drupal, affecting versions prior to 6.x-2.6. This vulnerability allows remote authenticated users to inject arbitrary web scripts or HTML into the application through exposed filters in the Views UI administrative interface and the view name parameter within the define custom views feature. The second vector of exploitation can only be executed by users with administrator-level permissions for the Views feature.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.