CVE-2008-0274
Published: 15 January 2008
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
Notes
Author | Note |
---|---|
jdstrand | according to Debian, needs register_globals On |
Priority
Status
Package | Release | Status |
---|---|---|
drupal Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
edgy |
Ignored
(end of life, was needed)
|
|
feisty |
Ignored
(end of life, was needed)
|
|
gutsy |
Does not exist
|
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Does not exist
|
|
upstream |
Needs triage
|
|
drupal5 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
edgy |
Does not exist
|
|
feisty |
Does not exist
|
|
gutsy |
Ignored
(end of life, was needed)
|
|
hardy |
Released
(5.6-1)
|
|
intrepid |
Released
(5.6-1)
|
|
jaunty |
Released
(5.6-1)
|
|
karmic |
Released
(5.6-1)
|
|
upstream |
Needs triage
|