CVE-2008-2998: XSS
Published Jul 3, 2008
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
15 affected components
Drupal Drupal=5.0
Drupal Drupal=5.1
Drupal Drupal=5.1_rev1.1
Drupal Drupal=5.2
Drupal Drupal=5.3
Drupal Drupal=5.4
Drupal Drupal=5.5.
Drupal Drupal=5.7
Drupal Aggregation module=3.0
Drupal Aggregation module=3.1
Drupal Aggregation module=3.2
Drupal Aggregation module=4.0
Drupal Aggregation module=4.1
Drupal Aggregation module=4.2
Drupal Aggregation module=4.3
Remediation
Patch Available
Event History
Jul 3, 2008
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Data Sourced
06:41 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-2998?
CVE-2008-2998 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-2998?
To mitigate CVE-2008-2998, update the Aggregation module for Drupal to version 5.x-4.4 or later.
3
What are the potential impacts of CVE-2008-2998?
The potential impacts of CVE-2008-2998 include allowing attackers to execute arbitrary web scripts or HTML on affected sites.
4
Which versions of Drupal are affected by CVE-2008-2998?
CVE-2008-2998 affects Drupal Aggregation module versions prior to 5.x-4.4.
5
Can CVE-2008-2998 be exploited remotely?
Yes, CVE-2008-2998 can be exploited remotely by attackers to inject malicious scripts.