CVE-2013-6387 - CERT CVE
ID CVE-2013-6387
Sažetak Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.
Reference
CVSS
Base: 2.1
Impact: 2.9
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL NONE
CVSS vektor AV:N/AC:H/Au:S/C:N/I:P/A:N
Zadnje važnije ažuriranje 04-01-2014 - 04:50
Objavljeno 24-12-2013 - 20:55