Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the autocomplete text field widget without Views.module.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2007-08-15T19:00:00
Updated: 2024-08-07T14:53:55.827Z
Reserved: 2007-08-15T00:00:00
Link: CVE-2007-4363
Vulnrichment
No data.
NVD
Status : Modified
Published: 2007-08-15T19:17:00.000
Modified: 2024-11-21T00:35:24.750
Link: CVE-2007-4363
Redhat
No data.