Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4370

Опубликовано: 21 дек. 2009
Источник: ubuntu
Приоритет: low
CVSS2: 3.5

Описание

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6.15-1
hardy

DNE

intrepid

DNE

jaunty

released

6.10-1ubuntu0.2
karmic

released

6.12-1.1ubuntu1.1
upstream

released

6.15

Показывать по

Ссылки на источники

3.5 Low

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

debian
больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/m ...

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

3.5 Low

CVSS2