LWN.net Logo

drupal-views: cross-site scripting

Package(s):drupal-views CVE #(s):
Created:January 4, 2011 Updated:January 5, 2011
Description: From the Drupal advisory:

The Views module provides a flexible method for Drupal site designers to control how lists and tables of content are presented. Under certain circumstances, Views could display parts of the page path without escaping, resulting in a relected Cross Site Scripting (XSS) vulnerability. An attacker could exploit this to gain full administrative access.

Alerts:
Fedora FEDORA-2010-18927 2010-12-17
Fedora FEDORA-2010-19009 2010-12-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds