CVE-2008-3095 (organic_groups_module_for_drupal) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-3095 (organic_groups_module_for_drupal)


Heap
10-07-08, 17:35
Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors.

More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3095)