← back
CVE-2010-2250

CVE-2010-2250

EPSS 1.0%
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Affected products
drupal6 · drupal6

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →