CVE-2010-2002
 
Severity Score
2.1
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo Wordfilter v5.x anteriores a v5.x-1.1 y 6.x anteriores v6.x-1.1 para Drupal permite a usuarios autenticados en remoto, con privilegios "administer words filtered", inyectar código web o HTML a través de una lista de palabras.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-05-20 CVE Reserved
- 2010-05-20 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/node/796618 | 2010-05-21 | |
http://drupal.org/node/796620 | 2010-05-21 | |
http://drupal.org/node/797208 | 2010-05-21 | |
http://www.securityfocus.com/bid/40119 | 2010-05-21 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/39811 | 2010-05-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Addison Berry Search vendor "Addison Berry" | Wordfilter Search vendor "Addison Berry" for product "Wordfilter" | 5.x-1.x Search vendor "Addison Berry" for product "Wordfilter" and version "5.x-1.x" | dev |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Jeff Warrington Search vendor "Jeff Warrington" | Wordfilter Search vendor "Jeff Warrington" for product "Wordfilter" | 5.x-1.0 Search vendor "Jeff Warrington" for product "Wordfilter" and version "5.x-1.0" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Jeff Warrington Search vendor "Jeff Warrington" | Wordfilter Search vendor "Jeff Warrington" for product "Wordfilter" | 6.x-1.0 Search vendor "Jeff Warrington" for product "Wordfilter" and version "6.x-1.0" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Jeff Warrington Search vendor "Jeff Warrington" | Wordfilter Search vendor "Jeff Warrington" for product "Wordfilter" | 6.x-1.x Search vendor "Jeff Warrington" for product "Wordfilter" and version "6.x-1.x" | dev |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|