|
|
| |
| This allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms. |
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1627
|
| |
Vulnerable Systems:
* Marvil07 Vote Up Down 6.x-3.0 Alpha1 and prior
Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal.
Vendor Status:
Vendor as issued an updated vulnerability.
Patch Availability:
http://drupalcode.org/project/vote_up_down.git/commit/fe83aa4b8fa44d83a01494870a80d4651434f4c0
CVE Information:
CVE-2012-1627
Disclosure Timeline:
Publish Date : 2012-09-15
Last Update Date : 2012-09-17
|
|
blog comments powered by
|