Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-3219

Опубликовано: 18 июл. 2008
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

feisty

ignored

end of life, was needs-triage
gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

released

5.8

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

feisty

DNE

gutsy

ignored

end of life, was needs-triage
hardy

released

5.7-1ubuntu1.1
intrepid

not-affected

5.9-1ubuntu1
jaunty

not-affected

5.9-1ubuntu1
karmic

not-affected

5.9-1ubuntu1
upstream

released

5.8

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

debian
почти 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before ...

github
около 3 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

4.3 Medium

CVSS2