CVE-2015-6665
published 2015-08-24CVE-2015-6665: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.69%
84.2th percentile
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| chaos_tool_suite_project | ctools | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
| drupal | drupal | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvm9-qc7j-544c: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7
ghsa_unreviewed·2022-05-17
CVE-2015-6665 [MEDIUM] CWE-79 GHSA-fvm9-qc7j-544c: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
OSV
CVE-2015-6665: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7
osv·2015-08-24·CVSS 4.3
CVE-2015-6665 [MEDIUM] CVE-2015-6665: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal7: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [epel-all]
bugzilla·2015-08-21·CVSS 4.3
CVE-2015-6658 [MEDIUM] CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal7: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [epel-all]
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal7: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003)
bugzilla·2015-08-21·CVSS 4.3
CVE-2015-6658 [MEDIUM] CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003)
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003)
Several issues were fixed in Drupal 6.37 and Drupal 7.39 core modules:
Cross-site Scripting (Ajax system - Drupal 7): CVE-2015-6665
Cross-site Scripting (Autocomplete system - Drupal 6 and 7): CVE-2015-6658
SQL Injection (Database API - Drupal 7): CVE-2015-6659
Cross-site Request Forgery (Form API - Drupal 6 and 7): CVE-2015-6660
Information Disclosure (Access system - Drupal 6 and 7): CVE-2015-6661
External reference:
https://www.drupal.org/SA-CORE-2015-003
Discussion:
Created drupal7 tracking bugs for this issue:
Affects: fedora-all [bug 1255672]
Affects: epel-all [bug 1255674]
---
Created drupal6 tracking bugs for this issue:
Affects: fedora-all [bug 1
Bugzilla
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal6: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [fedora-all]
bugzilla·2015-08-21·CVSS 4.3
CVE-2015-6658 [MEDIUM] CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal6: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [fedora-all]
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal6: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal7: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [fedora-all]
bugzilla·2015-08-21·CVSS 4.3
CVE-2015-6658 [MEDIUM] CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal7: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [fedora-all]
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal7: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal6: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [epel-all]
bugzilla·2015-08-21·CVSS 4.3
CVE-2015-6658 [MEDIUM] CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal6: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [epel-all]
CVE-2015-6658 CVE-2015-6659 CVE-2015-6660 CVE-2015-6661 CVE-2015-6665 drupal6: drupal: Several issues in 6.x and 7.x (SA-CORE-2015-003) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.htmlhttp://www.debian.org/security/2015/dsa-3346http://www.securityfocus.com/bid/76431http://www.securitytracker.com/id/1033358https://www.drupal.org/SA-CORE-2015-003https://www.drupal.org/node/2554133https://www.drupal.org/node/2554145http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.htmlhttp://www.debian.org/security/2015/dsa-3346http://www.securityfocus.com/bid/76431http://www.securitytracker.com/id/1033358https://www.drupal.org/SA-CORE-2015-003https://www.drupal.org/node/2554133https://www.drupal.org/node/2554145
2015-08-24
Published