Vulnerabilities
Vulnerable Software
Drupal:  >> Logintoboggan Module  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the username by removing certain characters, so this might not be a vulnerability on default installations.
CVSS Score
4.3
EPSS Score
0.005
Published
2007-07-17
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission to inject arbitrary JavaScript and gain privileges via "the message displayed above the default user login block."
CVSS Score
3.5
EPSS Score
0.002
Published
2007-07-17


Contact Us

Shodan ® - All rights reserved