Unrated severityNVD Advisory· Published Feb 23, 2010· Updated Apr 29, 2026
CVE-2010-0697
CVE-2010-0697
Description
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.
Affected products
8cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-1.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-1.1:*:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-1.x-dev:*:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-2.1:*:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-2.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-2.2:*:*:*:*:*:*:*
- cpe:2.3:a:ilya_ivanchenko:itweak_upload:6.x-2.x-dev:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- drupal.org/node/711072nvdPatch
- drupal.org/node/711074nvdPatch
- drupal.org/node/717214nvdPatchVendor Advisory
- www.securityfocus.com/bid/38292nvdPatch
- secunia.com/advisories/38633nvdVendor Advisory
- osvdb.org/62405nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/56351nvd
News mentions
0No linked articles in our index yet.