CVE Vulnerabilities

CVE-2006-4360

Published: Aug 27, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the create products permission to inject arbitrary web script or HTML via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Drupal_e-commerce_module Drupal 4.7 (including) 4.7 (including)

References