Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal 跨站脚本漏洞
Vulnerability Description
Drupal是Drupal社区的一套使用PHP语言开发的开源内容管理系统。 Drupal 5.8之前的5.x版本和 6.3之前的6.x版本和 filter_xss_admin 函数 不会阻止对象HTML标签在管理输入中的使用,具有未明影响和攻击向量,可能与跨站脚本攻击不充分的保护装置有关。
CVSS Information
N/A
Vulnerability Type
N/A