Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Drupal Content Creation Kit Module Multiple HTML Injection Vulnerabilities

The Content Creation Kit (CCK) module for Drupal is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input data.

Exploiting these issues may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.

These issues affect versions prior to CCK 5.x-1.8.







 

Privacy Statement
Copyright 2009, SecurityFocus