1 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 9EXPL: 0

30 Nov 2012 — Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el módulo Hashcash v6.x-2.x antes de v6.x-2.6 y v7.x-2.x antes de v7.x-2.2 para Drupal, cuando está habilit... • http://drupal.org/node/1650784 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •