Unrated severityNVD Advisory· Published May 19, 2010· Updated Apr 29, 2026
CVE-2010-1584
CVE-2010-1584
Description
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.
Affected products
12cpe:2.3:a:steven_jones:context:6.x-2.0:alpha1:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:steven_jones:context:6.x-2.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:6.x-2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:steven_jones:context:*:rc3:*:*:*:*:*:*range: <=6.x-2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- drupal.org/node/795118nvdPatch
- www.packetstormsecurity.com/1005-exploits/drupalab-xss.txtnvdExploit
- crackingdrupal.com/blog/greggles/mitigation-against-cve-2010-1584-drupal-context-module-xssnvd
- drupal.org/cvsnvd
- drupal.org/node/794718nvd
- www.madirish.netnvd
- www.securityfocus.com/bid/40056nvd
- www.theregister.co.uk/2010/05/10/drupal_security_bug/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/58521nvd
News mentions
0No linked articles in our index yet.