CVE-2008-6229: XSS
Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6229?
CVE-2008-6229 is classified as a medium severity vulnerability allowing XSS attacks in Drupal's Content Construction Kit.
How do I fix CVE-2008-6229?
To fix CVE-2008-6229, update to Drupal Content Construction Kit versions 5.x-1.10 or 6.x-2.0 or newer.
Who is affected by CVE-2008-6229?
CVE-2008-6229 affects remote authenticated users with 'administer content' permissions on the specified versions of Drupal Content Construction Kit.
What are the impacts of CVE-2008-6229?
CVE-2008-6229 can allow attackers to inject arbitrary scripts or HTML into the administrative interface, potentially compromising the site.
Can CVE-2008-6229 be exploited easily?
Yes, CVE-2008-6229 can be exploited easily by authenticated users with the appropriate permissions.