CVE-2008-6275: XSS
Published Feb 25, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
Affected Software
28 affected components
Drupal User Karma module<=5.x-1.12
Drupal User Karma module<=6.x-1.xdev
Drupal User Karma module=5.x-1.1
Drupal User Karma module=5.x-1.2
Drupal User Karma module=5.x-1.3
Drupal User Karma module=5.x-1.4
Drupal User Karma module=5.x-1.5
Drupal User Karma module=5.x-1.6
Drupal User Karma module=5.x-1.7
Drupal User Karma module=5.x-1.8
Drupal User Karma module=5.x-1.9
Drupal User Karma module=5.x-1.10
Drupal User Karma module=5.x-1.xdev
Joomla Joomla\!
All of the following
Any of the following
Drupal User Karma module<=5.x-1.12
Drupal User Karma module<=6.x-1.xdev
Drupal User Karma module=5.x-1.1
Drupal User Karma module=5.x-1.2
Drupal User Karma module=5.x-1.3
Drupal User Karma module=5.x-1.4
Drupal User Karma module=5.x-1.5
Drupal User Karma module=5.x-1.6
Drupal User Karma module=5.x-1.7
Drupal User Karma module=5.x-1.8
Drupal User Karma module=5.x-1.9
Drupal User Karma module=5.x-1.10
Drupal User Karma module=5.x-1.xdev
Joomla Joomla\!
Remediation
Patch Available
Patch Available
Event History
Feb 25, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·11:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6275?
CVE-2008-6275 has a moderate severity rating as it allows for cross-site scripting, potentially compromising user data.
2
How do I fix CVE-2008-6275?
To fix CVE-2008-6275, upgrade the User Karma module to version 5.x-1.13 or 6.x-1.0-beta1 or later.
3
Which Drupal versions are affected by CVE-2008-6275?
CVE-2008-6275 affects User Karma module versions prior to 5.x-1.13 and 6.x-1.0-beta1.
4
Can CVE-2008-6275 affect my website if I am using a later version of the User Karma module?
No, if you are using version 5.x-1.13 or later or 6.x-1.0-beta1 or later, you are not vulnerable to CVE-2008-6275.
5
What type of vulnerability is CVE-2008-6275 categorized as?
CVE-2008-6275 is categorized as a cross-site scripting (XSS) vulnerability.