CVE-2010-1958

Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
OR cpe:2.3:a:quicksketch:filefield:5.x-1.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.0:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.1:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.2:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:rc2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:rc3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.3:rc4:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.4:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:5.x-2.x-dev:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:beta1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:beta2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-1.0:beta3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:alpha7:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.1:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.2:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.3:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.5:*:*:*:*:*:*:*
cpe:2.3:a:quicksketch:filefield:6.x-3.x-dev:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-06-21 19:30

Updated : 2024-02-04 17:54


NVD link : CVE-2010-1958

Mitre link : CVE-2010-1958

CVE.ORG link : CVE-2010-1958


JSON object : View

Products Affected

quicksketch

  • filefield

drupal

  • drupal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')