2 results (0.010 seconds)

CVSS: 3.5EPSS: 0%CPEs: 28EXPL: 0

Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label. Vulnerabilidad de XSS en el módulo Custom Search 6.x-1.x anterior a 6.x-1.13 y 7.x-1.x anterior a 7.x-1.15 para Drupal permite a usuarios remotos autenticados con el permiso 'administrar taxonomía' inyectar secuencias de comandos web o HTML arbitrarios a través de una etiqueta del vocabulario de la taxonomía. • http://drupal.org/node/2248077 http://secunia.com/advisories/58209 http://www.securityfocus.com/bid/67062 https://exchange.xforce.ibmcloud.com/vulnerabilities/92754 https://www.drupal.org/node/2247919 https://www.drupal.org/node/2247921 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 3.5EPSS: 0%CPEs: 26EXPL: 0

Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom search" permission to inject arbitrary web script or HTML via the "Label text" field to admin/config/search/custom_search/results. Vulnerabilidad de XSS en el módulo Custom Search 6.x-1.x anterior a 6.x-1.12 y 7.x-1.x anterior a 7.x-1.14 para Drupal permite a usuarios remotos autenticados con el permiso 'administrar la búsqueda personalizada' inyectar secuencias de comandos web o HTML arbitrarios a través del campo 'etiquetar texto' en admin/config/search/custom_search/results. • http://seclists.org/fulldisclosure/2014/Apr/41 https://www.drupal.org/node/2231531 https://www.drupal.org/node/2231533 https://www.drupal.org/node/2231665 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •