Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2010-1584

Description

Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.

POC

Reference

- http://drupal.org/node/794718

- http://www.madirish.net/?article=457

- http://www.packetstormsecurity.com/1005-exploits/drupalab-xss.txt

- http://www.theregister.co.uk/2010/05/10/drupal_security_bug/

Github

No PoCs found on GitHub currently.