CVE-2010-0697
Drupal iTweak Upload module <6.x-1.2/<6.x-2.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.
References (7)
Scores
EPSS
0.0020
EPSS Percentile
41.7%
Classification
CWE
CWE-79
Status
published
Affected Products (9)
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
n/a/n/a
Timeline
Published
Feb 23, 2010
Tracked Since
Feb 18, 2026