CVE-2014-1607
Drupal 7.14 EventCalendar Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future
** DISPUTADA ** Vulnerabilidad de XSS en el módulo EventCalendar para Drupal 7.14 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través del parámetro year en eventcalander/. NOTA: este problema ha sido disputado por el equipo de seguridad de Drupal; puede resultar ser especifico a un sitio. Si esto es el caso, este CVE será RECHAZADA en el futuro.
Drupal version 7.14 EventCalendar suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-18 CVE Reserved
- 2014-01-25 CVE Published
- 2014-01-25 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://osvdb.org/102574 | Vdb Entry | |
http://www.securityfocus.com/archive/1/530876/100/0/threaded | Mailing List | |
https://groups.drupal.org/node/402023 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/124947 | 2014-01-25 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|