Unrated severityNVD Advisory· Published Aug 27, 2006· Updated Apr 16, 2026
CVE-2006-4360
CVE-2006-4360
Description
Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.
Affected products
1- cpe:2.3:a:drupal:drupal_e-commerce_module:4.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- drupal.org/node/80084nvdPatch
- secunia.com/advisories/21604nvdPatchVendor Advisory
- www.securityfocus.com/bid/19675nvdPatch
- www.vupen.com/english/advisories/2006/3364nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28528nvd
News mentions
0No linked articles in our index yet.