CVE-2006-5475

Drupal 4.6.x-4.7.x - Cross-Site Scripting via RSS Feed XML Parser

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29922
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1766
Various Sources x_refsource_confirm
http://drupal.org/node/88826
Vendor Advisory vendor-advisory x_refsource_openpkg
http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.025-drupal.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/449197/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22486
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4120

Scores

EPSS 0.0163
EPSS Percentile 82.1%

Details

Status published
Products (14)
drupal/drupal 4.6.0
drupal/drupal 4.6.1
drupal/drupal 4.6.2
drupal/drupal 4.6.3
drupal/drupal 4.6.4
drupal/drupal 4.6.5
drupal/drupal 4.6.6
drupal/drupal 4.6.7
drupal/drupal 4.6.8
drupal/drupal 4.6.9
... and 4 more
Published Oct 24, 2006
Tracked Since Feb 18, 2026