Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in the Data module 6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal allow remote authenticated users with the administer data tables permission to inject arbitrary web script or HTML via the title parameter in (1) data.views.inc and (2) data_ui/data_ui.admin.inc.
Software | From | Fixed in |
---|---|---|
alex_barth / data | 6.x-1.0-alpha10 | 6.x-1.0-alpha10.x |
alex_barth / data | 6.x-1.0-alpha13 | 6.x-1.0-alpha13.x |
alex_barth / data | 6.x-1.0-alpha1 | 6.x-1.0-alpha1.x |
alex_barth / data | 6.x-1.0-alpha9 | 6.x-1.0-alpha9.x |
alex_barth / data | 6.x-1.0-alpha7 | 6.x-1.0-alpha7.x |
alex_barth / data | 6.x-1.0-alpha4 | 6.x-1.0-alpha4.x |
alex_barth / data | 6.x-1.0-alpha5 | 6.x-1.0-alpha5.x |
alex_barth / data | 6.x-1.0-alpha3 | 6.x-1.0-alpha3.x |
alex_barth / data | 6.x-1.0-alpha11 | 6.x-1.0-alpha11.x |
alex_barth / data | 6.x-1.0-alpha12 | 6.x-1.0-alpha12.x |
alex_barth / data | 6.x-1.0-alpha2 | 6.x-1.0-alpha2.x |
alex_barth / data | 6.x-1.0-alpha8 | 6.x-1.0-alpha8.x |
alex_barth / data | 6.x-1.0-alpha6 | 6.x-1.0-alpha6.x |
alex_barth / data | 6.x-1.0-alpha14 | 6.x-1.0-alpha14.x |
alex_barth / data | 6.x-1.x-dev | 6.x-1.x-dev.x |
alex_barth / data | 7.x-1.0-alpha2 | 7.x-1.0-alpha2.x |
alex_barth / data | 7.x-1.0-alpha1 | 7.x-1.0-alpha1.x |
alex_barth / data | 7.x-1.x-dev | 7.x-1.x-dev.x |