Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote attackers to inject arbitrary web script or HTML via the motivation field in the CVS application page, which is not passed through check_markup on display.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal CVS Management/Tracker Motivation Field跨站脚本攻击漏洞
Vulnerability Description
用于Drupal的CVS management/tracker 4.7.x-1.0、4.7.x-2.0和4.7.0(20060807 contribution release system之前)存在跨站脚本攻击(XSS)漏洞,远程攻击者可通过在CVS应用程序页的motivation字段(显示时不通过check_markup传递)来注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A