Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4369

Опубликовано: 21 дек. 2009
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 3.5

Описание

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

5.7-1ubuntu1.2
intrepid

released

5.10-1ubuntu1.1
jaunty

released

5.15-1ubuntu1.2
karmic

released

5.18-1.1ubuntu2.1
upstream

released

5.21

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6.15-1
hardy

DNE

intrepid

DNE

jaunty

released

6.10-1ubuntu0.2
karmic

released

6.12-1.1ubuntu1.1
upstream

released

6.15

Показывать по

EPSS

Процентиль: 49%
0.00256
Низкий

3.5 Low

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

debian
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (module ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

EPSS

Процентиль: 49%
0.00256
Низкий

3.5 Low

CVSS2