LOW
drupal-service_links: xss vulnerability
Published Oct 9, 2009
3.5
LOWCVSS 2.0
EPSS 1.36%
Description
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names.
Affected products
No data.
AND
- 6.x-1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://www.madirish.net/?article=251 x_refsource_MISCExploitPatch
- http://www.securityfocus.com/bid/36584 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-3648 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=528200 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53633 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3648
- https://www.cve.org/CVERecord?id=CVE-2009-3648
| Link | Providers | Tags |
|---|---|---|
| http://www.madirish.net/?article=251 | x_refsource_MISCExploitPatch | |
| http://www.securityfocus.com/bid/36584 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2009-3648 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=528200 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/53633 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3648 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-3648 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 9, 2009
Updated Aug 7, 2024
Reserved Oct 9, 2009
Link CVE-2009-3648
CISA Vulnrichment
Updated n/a