Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.
References
Link | Resource |
---|---|
http://drupal.org/node/764906 | Patch |
http://drupal.org/node/764998 | Patch Vendor Advisory |
http://osvdb.org/63589 | |
http://secunia.com/advisories/39361 | Vendor Advisory |
http://www.securityfocus.com/bid/39304 | Patch |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2010-04-26 18:30
Updated : 2024-02-04 17:54
NVD link : CVE-2010-1530
Mitre link : CVE-2010-1530
CVE.ORG link : CVE-2010-1530
JSON object : View
Products Affected
reyero
- i18n
drupal
- drupal
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')