CVE
- Id
- 83942
- CVE No.
- CVE-2015-6665
- Status
- Candidate
- Description
- Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
- Phase
- Assigned (20150824)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
745323 | 83942 | CVE-2015-6665 | MISC:https://www.drupal.org/node/2554145 | View |
745324 | 83942 | CVE-2015-6665 | CONFIRM:https://www.drupal.org/SA-CORE-2015-003 | View |
745325 | 83942 | CVE-2015-6665 | CONFIRM:https://www.drupal.org/node/2554133 | View |
745326 | 83942 | CVE-2015-6665 | DEBIAN:DSA-3346 | View |
745327 | 83942 | CVE-2015-6665 | URL:http://www.debian.org/security/2015/dsa-3346 | View |
745328 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-14329 | View |
745329 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.html | View |
745330 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-14330 | View |
745331 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.html | View |
745332 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-14331 | View |
745333 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.html | View |
745334 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-13916 | View |
745335 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.html | View |
745336 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-13917 | View |
745337 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.html | View |
745338 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-14442 | View |
745339 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.html | View |
745340 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-14443 | View |
745341 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.html | View |
745342 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-14444 | View |
745343 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.html | View |
745344 | 83942 | CVE-2015-6665 | FEDORA:FEDORA-2015-13915 | View |
745345 | 83942 | CVE-2015-6665 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html | View |
745346 | 83942 | CVE-2015-6665 | BID:76431 | View |
745347 | 83942 | CVE-2015-6665 | URL:http://www.securityfocus.com/bid/76431 | View |
745348 | 83942 | CVE-2015-6665 | SECTRACK:1033358 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
9954 | JVNDB-2015-005274 | Windows および Mac OS X 上で稼働する Adobe Reader および Acrobat の DynamicAnnotStore メソッドにおける JavaScript API 実行の制限を回避される脆弱性 | Windows および Mac OS X 上で稼働する Adobe Reader および Acrobat の DynamicAnnotStore メソッドには、JavaScript API 実行の制限を回避される脆弱性が存在します。 | CVE-2015-6717 | 83942 | 9.3 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-005274.html | View |