Cross-Site Scripting Vulnerability in Drupal Views Module
CVE-2009-2076
Currently unrated
What is CVE-2009-2076?
A cross-site scripting (XSS) vulnerability exists in the Views module for Drupal, affecting versions prior to 6.x-2.6. This vulnerability allows remote authenticated users to inject arbitrary web scripts or HTML into the application through exposed filters in the Views UI administrative interface and the view name parameter within the define custom views feature. The second vector of exploitation can only be executed by users with administrator-level permissions for the Views feature.