CVE-2005-0682

Drupal < 4.5.2 - Cross-Site Scripting via Common.inc Inputs

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

References (3)

Core 3
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14515
Patch, Vendor Advisory x_refsource_confirm
http://drupal.org/drupal-4.5.2

Scores

EPSS 0.0036
EPSS Percentile 58.6%

Details

Status published
Products (5)
drupal/drupal 4.4.0
drupal/drupal 4.4.1
drupal/drupal 4.4.2
drupal/drupal 4.5.0
drupal/drupal 4.5.1
Published May 02, 2005
Tracked Since Feb 18, 2026