Vulnerability Database

290,206

Total vulnerabilities in the database

CVE-2015-6665

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.

  • Published: Aug 24, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-6665
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
fedoraproject / fedora 22 22.x
fedoraproject / fedora 23 23.x
fedoraproject / fedora 21 21.x
drupal / drupal 7.0-alpha5 7.0-alpha5.x
drupal / drupal 7.0-dev 7.0-dev.x
drupal / drupal 7.0-alpha7 7.0-alpha7.x
drupal / drupal 7.16 7.16.x
drupal / drupal 7.21 7.21.x
drupal / drupal 7.0-rc2 7.0-rc2.x
drupal / drupal 7.18 7.18.x
drupal / drupal 7.15 7.15.x
drupal / drupal 7.0-rc4 7.0-rc4.x
drupal / drupal 7.38 7.38.x
drupal / drupal 7.0-beta2 7.0-beta2.x
drupal / drupal 7.0-rc3 7.0-rc3.x
drupal / drupal 7.0-alpha1 7.0-alpha1.x
drupal / drupal 7.3 7.3.x
drupal / drupal 7.17 7.17.x
drupal / drupal 7.8 7.8.x
drupal / drupal 7.0-alpha4 7.0-alpha4.x
drupal / drupal 7.13 7.13.x
drupal / drupal 7.35 7.35.x
drupal / drupal 7.20 7.20.x
drupal / drupal 7.5 7.5.x
drupal / drupal 7.10 7.10.x
drupal / drupal 7.30 7.30.x
drupal / drupal 7.27 7.27.x
drupal / drupal 7.6 7.6.x
drupal / drupal 7.12 7.12.x
drupal / drupal 7.34 7.34.x
drupal / drupal 7.9 7.9.x
drupal / drupal 7.0-rc1 7.0-rc1.x
drupal / drupal 7.0-beta3 7.0-beta3.x
drupal / drupal 7.4 7.4.x
drupal / drupal 7.x-dev 7.x-dev.x
drupal / drupal 7.28 7.28.x
drupal / drupal 7.22 7.22.x
drupal / drupal 7.0-alpha2 7.0-alpha2.x
drupal / drupal 7.11 7.11.x
drupal / drupal 7.33 7.33.x
drupal / drupal 7.0-alpha6 7.0-alpha6.x
drupal / drupal 7.19 7.19.x
drupal / drupal 7.25 7.25.x
drupal / drupal 7.0 7.0.x
drupal / drupal 7.24 7.24.x
drupal / drupal 7.14 7.14.x
drupal / drupal 7.23 7.23.x
drupal / drupal 7.26 7.26.x
drupal / drupal 7.0-beta1 7.0-beta1.x
drupal / drupal 7.29 7.29.x
drupal / drupal 7.1 7.1.x
drupal / drupal 7.7 7.7.x
drupal / drupal 7.0-alpha3 7.0-alpha3.x
drupal / drupal 7.2 7.2.x
drupal / drupal 7.37 7.37.x
drupal / drupal 7.36 7.36.x
chaos_tool_suite_project / ctools 6.x-1.0-beta4 6.x-1.0-beta4.x
chaos_tool_suite_project / ctools 6.x-1.0-alpha2 6.x-1.0-alpha2.x
chaos_tool_suite_project / ctools 6.x-1.1 6.x-1.1.x
chaos_tool_suite_project / ctools 6.x-1.0-beta3 6.x-1.0-beta3.x
chaos_tool_suite_project / ctools 6.x-1.0-rc1 6.x-1.0-rc1.x
chaos_tool_suite_project / ctools 6.x-1.7 6.x-1.7.x
chaos_tool_suite_project / ctools 6.x-1.6 6.x-1.6.x
chaos_tool_suite_project / ctools 6.x-1.0-alpha1 6.x-1.0-alpha1.x
chaos_tool_suite_project / ctools 6.x-1.0 6.x-1.0.x
chaos_tool_suite_project / ctools 6.x-1.4 6.x-1.4.x
chaos_tool_suite_project / ctools 6.x-1.9 6.x-1.9.x
chaos_tool_suite_project / ctools 6.x-1.x-dev 6.x-1.x-dev.x
chaos_tool_suite_project / ctools 6.x-1.0-alpha3 6.x-1.0-alpha3.x
chaos_tool_suite_project / ctools 6.x-1.0-beta2 6.x-1.0-beta2.x
chaos_tool_suite_project / ctools 6.x-1.11 6.x-1.11.x
chaos_tool_suite_project / ctools 6.x-1.2 6.x-1.2.x
chaos_tool_suite_project / ctools 6.x-1.5 6.x-1.5.x
chaos_tool_suite_project / ctools 6.x-1.13 6.x-1.13.x
chaos_tool_suite_project / ctools 6.x-1.0-beta1 6.x-1.0-beta1.x
chaos_tool_suite_project / ctools 6.x-1.3 6.x-1.3.x
chaos_tool_suite_project / ctools 6.x-1.8 6.x-1.8.x
chaos_tool_suite_project / ctools 6.x-1.12 6.x-1.12.x