CVE-2008-2849: XSS
Published Jun 25, 2008
·Updated
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Drupal TrailScout module=5
Event History
Jun 25, 2008
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2849?
CVE-2008-2849 is classified as a critical cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2008-2849?
To fix CVE-2008-2849, update the TrailScout module to version 5.x-1.4 or later.
3
Who is affected by CVE-2008-2849?
Remote authenticated users with create post permissions are affected by CVE-2008-2849.
4
What types of attacks does CVE-2008-2849 enable?
CVE-2008-2849 allows attackers to inject arbitrary web scripts or HTML into the affected application.
5
Which versions of the TrailScout module are vulnerable to CVE-2008-2849?
All versions of the TrailScout module prior to 5.x-1.4 are vulnerable to CVE-2008-2849.