CVE-2007-5596
Publication date 19 October 2007
Last updated 24 July 2024
Ubuntu priority
The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.
Status
Package | Ubuntu Release | Status |
---|---|---|
drupal5 | 7.10 gutsy |
Fixed 5.2-2ubuntu2.1
|
7.04 feisty | Not in release | |
6.10 edgy | Not in release | |
6.06 LTS dapper | Not in release |