CVE-2015-6665
CVE-2015-6665
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.htmlhttps://www.drupal.org/node/2554133https://www.drupal.org/node/2554145https://www.drupal.org/SA-CORE-2015-003