CVE-2008-3097: XSS
Published Jul 9, 2008
·Updated
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.
Affected Software
1 affected component
Drupal Tinytax Taxonomy Block Module=5
Event History
Jul 9, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3097?
CVE-2008-3097 has a medium severity level due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2008-3097?
To fix CVE-2008-3097, upgrade the Tinytax module to version 5.x-1.10-1 or later.
3
Who is affected by CVE-2008-3097?
CVE-2008-3097 affects remote authenticated users of the Tinytax module in Drupal 5.x before the specified patched version.
4
What type of vulnerability is CVE-2008-3097?
CVE-2008-3097 is categorized as a cross-site scripting (XSS) vulnerability.
5
Can remote users exploit CVE-2008-3097?
Yes, remote authenticated users can exploit CVE-2008-3097 to inject arbitrary web scripts or HTML.