Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.
Software | From | Fixed in |
---|---|---|
drupal / faq | 6.x-1.9 | 6.x-1.9.x |
drupal / faq | 6.x-1.7 | 6.x-1.7.x |
drupal / faq | 6.x-1.3 | 6.x-1.3.x |
drupal / faq | 6.x-1.8 | 6.x-1.8.x |
drupal / faq | 6.x-1.6 | 6.x-1.6.x |
drupal / faq | 6.x-1.11 | 6.x-1.11.x |
drupal / faq | 6.x-1.10 | 6.x-1.10.x |
drupal / faq | 6.x-1.5 | 6.x-1.5.x |
drupal / faq | 6.x-1.x | 6.x-1.x.x |
drupal / faq | 6.x-1.1 | 6.x-1.1.x |
drupal / faq | 6.x-1.0 | 6.x-1.0.x |
drupal / faq | 6.x-1.2 | 6.x-1.2.x |
drupal / faq | 6.x-1.12 | 6.x-1.12.x |
drupal / faq | 6.x-1.4 | 6.x-1.4.x |
drupal / faq | 7x-1.x-rc1 | 7x-1.x-rc1.x |