Логотип exploitDog
bind:CVE-2009-4371
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-4371

Количество 4

Количество 4

ubuntu логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
EPSS: Низкий
github логотип

GHSA-cv5p-xvxc-9fqp

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
github логотип
GHSA-cv5p-xvxc-9fqp

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу