CVE-2012-2298
https://notcve.org/view.php?id=CVE-2012-2298
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks." Múltiples vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en el módulo realname v6.x-1.x antes de v6.x-1.5 para Drupal permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores relacionados con (1) los nombres de usuario "en la página títulos" y (2) "las llamadas a autocompletar". • http://drupal.org/node/1547352 http://drupal.org/node/1547660 http://drupalcode.org/project/realname.git/commitdiff/41786d0 http://drupalcode.org/project/realname.git/commitdiff/b920794 http://secunia.com/advisories/48936 http://www.openwall.com/lists/oss-security/2012/05/03/1 http://www.openwall.com/lists/oss-security/2012/05/03/2 http://www.securityfocus.com/bid/53250 https://exchange.xforce.ibmcloud.com/vulnerabilities/75181 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2009-4524
https://notcve.org/view.php?id=CVE-2009-4524
Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (aka real name) element. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo RealName v6.x-1.x anteriores a 6.x-1.3 para Drupal, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del elemento realname (también conocido como name). • http://drupal.org/node/604760 http://osvdb.org/58944 http://secunia.com/advisories/37058 http://www.securityfocus.com/bid/36699 http://www.vupen.com/english/advisories/2009/2921 https://exchange.xforce.ibmcloud.com/vulnerabilities/53787 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •