[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-4369Date: (C)2009-12-21   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-37372
SECUNIA-37815
SECUNIA-37824
drupal-contact-xss(54867)
http://drupal.org/files/sa-core-2009-009/SA-CORE-2009-009-6.14.patch
http://drupal.org/node/661586
http://www.madirish.net/?article=441

CPE    43
cpe:/a:drupal:drupal:5.0:rc1
cpe:/a:drupal:drupal:6.1
cpe:/a:drupal:drupal:6.0
cpe:/a:drupal:drupal:5.11
...
CWE    1
CWE-79

© SecPod Technologies