Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2372

Опубликовано: 08 июл. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.5

Описание

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6.12-1.1ubuntu1
hardy

DNE

intrepid

DNE

jaunty

released

6.10-1ubuntu0.1
upstream

released

6.13

Показывать по

EPSS

Процентиль: 77%
0.01134
Низкий

6.5 Medium

CVSS2

Связанные уязвимости

nvd
почти 16 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

debian
почти 16 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user sign ...

github
около 3 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS

Процентиль: 77%
0.01134
Низкий

6.5 Medium

CVSS2