Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-1958


Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).


Published

2010-06-21T19:30:01.943

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.1 (LOW)

CVSSv2 Vector

AV:N/AC:H/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application drupal drupal * No
Application quicksketch filefield 5.x-1.x-dev Yes
Application quicksketch filefield 5.x-2.0 Yes
Application quicksketch filefield 5.x-2.1 Yes
Application quicksketch filefield 5.x-2.2 Yes
Application quicksketch filefield 5.x-2.3 Yes
Application quicksketch filefield 5.x-2.3 Yes
Application quicksketch filefield 5.x-2.3 Yes
Application quicksketch filefield 5.x-2.3 Yes
Application quicksketch filefield 5.x-2.4 Yes
Application quicksketch filefield 5.x-2.x-dev Yes
Application quicksketch filefield 6.x-1.0 Yes
Application quicksketch filefield 6.x-1.0 Yes
Application quicksketch filefield 6.x-1.0 Yes
Application quicksketch filefield 6.x-1.0 Yes
Application quicksketch filefield 6.x-1.0 Yes
Application quicksketch filefield 6.x-1.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.0 Yes
Application quicksketch filefield 6.x-3.1 Yes
Application quicksketch filefield 6.x-3.2 Yes
Application quicksketch filefield 6.x-3.3 Yes
Application quicksketch filefield 6.x-3.5 Yes
Application quicksketch filefield 6.x-3.x-dev Yes

References