NVD

Id
13449  
Name
CVE-2010-1958  
Description
Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and "Path to File" or "URL to File" display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).  
Reject
 
CVSS Version
2  
CVSS Score
2.1  
Severity
Low  
CVSS Base Score
2.1  
CVSS Impact Subscore
2.9  
CVSS Exploit Subscore
3.9  
CVSS Vector
(AV:N/AC:H/Au:S/C:N/I:P/A:N)  
Pub Date
2017-01-18  
Published
2010-06-21  
Modified Date
2010-06-22  
Seq
2010-1958  

Actions