CVE-2014-8765
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and return the results to the PIFR_Server test results page or (2) remote authenticated users with the "manage PIFR environments" permission to inject arbitrary web script or HTML via vectors involving a PIFR_Server administrative page.
Múltiples vulnerabilidadaes de XSS en el módulo Project Issue File Review (PIFR) 6.x-2.x anterior a 6.x-2.17 para Drupal permiten a (1) atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un parche manipulado, lo que provoca un cliente PIFR para probar el parche y devolver los resultados a la página de los resultados de las pruebas PIFR_Server o (2) usuarios remotos autenticados con el permiso 'manejar entornos PIFR' inyectar secuencias de comandos web o HTML arbitrarios a través de vectores que involucran una página administrativa PIFR_Server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-14 CVE Reserved
- 2014-10-14 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/57030 | Third Party Advisory | |
http://www.securityfocus.com/bid/65830 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.drupal.org/node/2205755 | 2014-10-22 |
URL | Date | SRC |
---|---|---|
https://www.drupal.org/node/2205767 | 2014-10-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | <= 6.x-2.16 Search vendor "Drupal" for product "Project Issue File Review" and version " <= 6.x-2.16" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.00 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.00" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.01 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.01" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.02 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.02" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.03 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.03" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.04 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.04" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.05 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.05" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.06 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.06" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.07 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.07" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.08 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.08" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.08 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.08" | rc1 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.08 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.08" | rc2 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.08 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.08" | rc3 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.08 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.08" | rc4 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.10 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.10" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.12 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.12" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.12 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.12" | alpha1 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.12 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.12" | rc1 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.13 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.13" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.14 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.14" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.14 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.14" | beta1 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.14 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.14" | beta2 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.14 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.14" | beta3 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.14 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.14" | beta4 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.14 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.14" | beta5 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.15 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.15" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.15 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.15" | rc1 |
Affected
| ||||||
Drupal Search vendor "Drupal" | Project Issue File Review Search vendor "Drupal" for product "Project Issue File Review" | 6.x-2.15 Search vendor "Drupal" for product "Project Issue File Review" and version "6.x-2.15" | rc2 |
Affected
|