MEDIUM
drupal: multiple vulnerabilities in < 6.11 (SA-CORE-2009-005)
Published May 6, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.60%
Description
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.
Affected products
No data.
OR
- 5.0
- 5.0
- 5.0
- 5.0
- 5.0
- 5.1
- 5.1_rev1.1
- 5.2
- 5.3
- 5.4
- 5.5
- 5.5.
- 5.6
- 5.7
- 5.8
- 5.9
- 5.10
- 5.11
- 5.12
- 5.13
- 5.14
- 5.15
- 5.16
- 6
- 6
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.1
- 6.2
- 6.3
- 6.4
- 6.5
- 6.6
- 6.7
- 6.8
- 6.9
- 6.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://drupal.org/node/449078 x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/34948 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34950 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34980 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2009/dsa-1792 vendor-advisoryx_refsource_DEBIAN
- http://www.osvdb.org/54152 vdb-entryx_refsource_OSVDBPatch
- http://www.vbdrupal.org/forum/showthread.php?p=9953#post9953 x_refsource_CONFIRMPatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1216 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1575 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=498643 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1571 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50250 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1575
- https://www.cve.org/CVERecord?id=CVE-2009-1575
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00108.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00133.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 6, 2009
Updated Aug 7, 2024
Reserved May 6, 2009
Link CVE-2009-1575
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1571 Assigner mitre
Published May 6, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1571