Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and administer blocks, to inject arbitrary web script or HTML via the edit-title parameter (aka block title).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://secunia.com/advisories/38186 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/508933/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/55606 | vdb entry |
http://drupal.org/node/683584 | patch |
http://www.osvdb.org/61682 | patch vdb entry |
http://drupal.org/node/683598 | patch vendor advisory |
http://drupal.org/node/683586 | patch |
http://packetstormsecurity.org/1001-exploits/drupalnb-xss.txt | exploit |
http://www.securityfocus.com/bid/37782 | patch vdb entry |