Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | creative | 7.x-1.0 |
| devsaran | creative | 7.x-1.1 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | fresh | 7.x-1.2 |
| devsaran | fresh | 7.x-1.0 |
| devsaran | fresh | * |
| devsaran | fresh | 7.x-1.1 |
| devsaran | fresh | 7.x-1.x |
Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | best_responsive | 7.x-1.0 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | professional_theme | 7.x-1.2 |
| devsaran | professional_theme | * |
| devsaran | professional_theme | 7.x-1.x |
| devsaran | professional_theme | 7.x-1.1 |
| devsaran | professional_theme | 7.x-1.0 |
Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | responsive_blog | 7.x-1.0 |
| devsaran | responsive_blog | 7.x-1.1 |
| devsaran | responsive_blog | 7.x-1.5 |
| devsaran | responsive_blog | 7.x-1.4 |
| devsaran | responsive_blog | 7.x-1.2 |
| devsaran | responsive_blog | 7.x-1.3 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | business | 7.x-1.4 |
| devsaran | business | 7.x-1.7 |
| devsaran | business | * |
| devsaran | business | 7.x-1.5 |
| devsaran | business | 7.x-1.6 |
| devsaran | business | 7.x-1.1 |
| devsaran | business | 7.x-1.3 |
| devsaran | business | 7.x-1.2 |
| devsaran | business | 7.x-1.x |
| devsaran | business | 7.x-1.0 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | clean_theme | * |
| devsaran | clean_theme | 7.x-1.1 |
| devsaran | clean_theme | 7.x-1.0 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Premium Responsive theme before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | responsive | 7.x-1.3 |
| devsaran | responsive | 7.x-1.2 |
| devsaran | responsive | * |
| devsaran | responsive | 7.x-1.0 |
| devsaran | responsive | 7.x-1.4 |
| devsaran | responsive | 7.x-1.1 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | company | 7.x-1.0 |
| devsaran | company | 7.x-1.2 |
| devsaran | company | 7.x-1.1 |
| devsaran | company | * |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Simple Corporate theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| devsaran | corporate | 7.x-1.2 |
| devsaran | corporate | 7.x-1.1 |
| devsaran | corporate | 7.x-1.0 |
| devsaran | corporate | * |