Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-1660

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2012-1660
Last Modified 20 Dec 2012 12:00:00
Published 18 Sep 2012 04:55:02
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity HIGH
Authentication SINGLE_INSTANCE

CVE-2012-1660

Summary

Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios.

Vulnerable Systems

Application

  • Nathan Haug Webform 6.x-3.0

  • Nathan Haug Webform 6.x-3.1

  • Nathan Haug Webform 6.x-3.10

  • Nathan Haug Webform 6.x-3.11

  • Nathan Haug Webform 6.x-3.12

  • Nathan Haug Webform 6.x-3.13

  • Nathan Haug Webform 6.x-3.14

  • Nathan Haug Webform 6.x-3.15

  • Nathan Haug Webform 6.x-3.16

  • Nathan Haug Webform 6.x-3.2

  • Nathan Haug Webform 6.x-3.3

  • Nathan Haug Webform 6.x-3.4

  • Nathan Haug Webform 6.x-3.5

  • Nathan Haug Webform 6.x-3.6

  • Nathan Haug Webform 6.x-3.7

  • Nathan Haug Webform 6.x-3.8

  • Nathan Haug Webform 6.x-3.9

  • Nathan Haug Webform 6.x-3.x

  • Nathan Haug Webform 7.x-3.0

  • Nathan Haug Webform 7.x-3.10

  • Nathan Haug Webform 7.x-3.11

  • Nathan Haug Webform 7.x-3.12

  • Nathan Haug Webform 7.x-3.13

  • Nathan Haug Webform 7.x-3.15

  • Nathan Haug Webform 7.x-3.16

  • Nathan Haug Webform 7.x-3.3

  • Nathan Haug Webform 7.x-3.4

  • Nathan Haug Webform 7.x-3.6

  • Nathan Haug Webform 7.x-3.7

  • Nathan Haug Webform 7.x-3.8

  • Nathan Haug Webform 7.x-3.9

  • Nathan Haug Webform 7.x-3.x


References

XF - drupal-webform-unspecified-xss-var2(73779)

BID - 52345

OSVDB - 79852

MLIST - [oss-security] 20120406 CVE's for Drupal Contrib 2012 001 through 057 (67 new CVE assignments)

SECUNIA - 48310

CONFIRM - http://drupalcode.org/project/webform.git/commit/917fa91

CONFIRM - http://drupalcode.org/project/webform.git/commit/90af819

MISC - http://drupal.org/node/1472214

CONFIRM - http://drupal.org/node/1472180

CONFIRM - http://drupal.org/node/1472178


Last Updated: 27 May 2016 11:00:44