Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
References 5 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- http://drupal.org/node/1723532 x_transferred
- http://drupal.org/node/1929500 x_transferred
- openwall.com: [oss-security] 20130227 Re: CVE Request for Drupal Contributed Modules mailing-listx_transferred
- http://drupalcode.org/project/clean_theme.git/commitdiff/ff2da6f x_transferred
- http://drupalcode.org/project/clean_theme.git/commitdiff/697f839 x_transferred