CVE

Id
55541  
CVE No.
CVE-2012-2298  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks."  
Phase
Assigned (20120419)  
Votes
None (candidate not yet proposed)  
Comments