CVE-2012-4469 Information

Description

Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal when \Log failed hashcash\ is enabled allows remote attackers to inject arbitrary web script or HTML via an invalid token which is not properly handled when administrators use the Database logging module.

Reference

http://drupal.org/node/1650784 http://drupal.org/node/1650790 http://drupal.org/node/1663306 http://www.openwall.com/lists/oss-security/2012/10/04/3

Share on: