[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-4370Date: (C)2009-12-21   (M)2023-12-22


Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
BID-37372
SECUNIA-37815
drupal-menu-xss(54872)
http://drupal.org/files/sa-core-2009-009/SA-CORE-2009-009-6.14.patch
http://drupal.org/node/661586

CPE    19
cpe:/a:drupal:drupal:6.10
cpe:/a:drupal:drupal:6.11
cpe:/a:drupal:drupal:6.1
cpe:/a:drupal:drupal:6.12
...
CWE    1
CWE-79

© SecPod Technologies