First published: Thu Feb 19 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =5.10 | |
Drupal Drupal | =5.4 | |
Drupal Drupal | =6.2 | |
Drupal Drupal | =5.2 | |
Drupal Drupal | =5.7 | |
Drupal Drupal | =6.4 | |
Drupal Drupal | =5.0 | |
Drupal Drupal | =6.1 | |
Drupal Drupal | =5.6 | |
Drupal Drupal | =5.1 | |
Drupal Drupal | =6.5 | |
Drupal Drupal | =5.5 | |
Drupal Drupal | =6.0 | |
Drupal Drupal | =5.9 | |
Drupal Drupal | =5.8 | |
Drupal Drupal | =5.3 | |
Drupal Drupal | =6.3 | |
Drupal Drupal | =5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6170 is rated as a medium severity vulnerability.
To fix CVE-2008-6170, upgrade your Drupal installation to version 5.12 or 6.6 or later.
CVE-2008-6170 affects Drupal versions 5.x before 5.12 and 6.x before 6.6.
Remote authenticated users with create book content or edit node book hierarchy permissions can exploit CVE-2008-6170.
CVE-2008-6170 is a cross-site scripting (XSS) vulnerability.