CVE-2008-3097 (tinytax_taxonomy_block_module_for_drupal) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-3097 (tinytax_taxonomy_block_module_for_drupal)


Heap
10-07-08, 17:35
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3097)