MEDIUM
Cross-site scripting (XSS) vulnerability in the Flag Content module 5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Reason parameter
Published Sep 13, 2011
4.3
MEDIUMCVSS 2.0
EPSS 1.26%
Description
Cross-site scripting (XSS) vulnerability in the Flag Content module 5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Reason parameter.
Affected products
No data.
AND
OR
- 5.x-2.0
- 5.x-2.1
- 5.x-2.2
- 5.x-2.4
- 5.x-2.5
- 5.x-2.6
- 5.x-2.7
- 5.x-2.8
- 5.x-2.9
- 5.x-2.x-dev
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://drupal.org/node/610868 x_refsource_CONFIRMPatchVendor Advisory
- http://drupal.org/node/610870 x_refsource_CONFIRMPatch
- http://osvdb.org/59119 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/37124 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/36785 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2009/2999 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-5051 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53900 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://drupal.org/node/610868 | x_refsource_CONFIRMPatchVendor Advisory | |
| http://drupal.org/node/610870 | x_refsource_CONFIRMPatch | |
| http://osvdb.org/59119 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/37124 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/36785 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2009/2999 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-5051 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/53900 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 13, 2011
Updated Aug 7, 2024
Reserved Sep 13, 2011
Link CVE-2009-5096
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data