Unrated severityNVD Advisory· Published Jun 7, 2010· Updated Apr 29, 2026
CVE-2010-2158
CVE-2010-2158
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected products
49cpe:2.3:a:speedtech:storm:5.x-1.1:*:*:*:*:*:*:*+ 48 more
- cpe:2.3:a:speedtech:storm:5.x-1.1:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.2:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.3:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.4:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.5:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.6:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.7:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.8:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.9:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.10:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.11:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.12:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.13:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.14:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:5.x-1.x:dev:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.1:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.2:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.3:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.4:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.5:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.6:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.7:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.8:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.9:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.10:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.11:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.12:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.13:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.14:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.15:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.16:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.17:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.18:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.19:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.20:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.21:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.22:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.23:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.24:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.25:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.26:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.27:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.28:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.29:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.30:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.31:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.32:*:*:*:*:*:*:*
- cpe:2.3:a:speedtech:storm:6.x-1.x:dev:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- drupal.org/node/803770nvdPatchVendor Advisory
- secunia.com/advisories/39732nvdVendor Advisory
News mentions
0No linked articles in our index yet.