1 results (0.001 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack. El módulo Drupal Views Builk Operations (VBO) versiones 6.x-1.0 hasta 6.x-1.10, no escapa apropiadamente de la ayuda de vocabulario cuando el vocabulario ha habilitado el etiquetado del usuario y se utiliza la acción "Modify node taxonomy terms". Un atacante remoto podría proveer una URL especialmente diseñada que podría conllevar a un ataque de tipo cross-site scripting (XSS). • https://access.redhat.com/security/cve/cve-2011-3373 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3373 https://www.openwall.com/lists/oss-security/2011/09/22/4 https://www.securityfocus.com/bid/49727 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •