CVE-2009-1575: XSS
Published May 6, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.
Affected Software
44 affected components
Drupal Drupal=5.0
Drupal Drupal=5.0-beta1
Drupal Drupal=5.0-beta2
Drupal Drupal=5.0-rc1
Drupal Drupal=5.0-rc2
Drupal Drupal=5.1
Drupal Drupal=5.1_rev1.1
Drupal Drupal=5.2
Drupal Drupal=5.3
Drupal Drupal=5.4
Drupal Drupal=5.5
Drupal Drupal=5.5.
Drupal Drupal=5.6
Drupal Drupal=5.7
Drupal Drupal=5.8
Drupal Drupal=5.9
Drupal Drupal=5.10
Drupal Drupal=5.11
Drupal Drupal=5.12
Drupal Drupal=5.13
Drupal Drupal=5.14
Drupal Drupal=5.15
Drupal Drupal=5.16
Drupal Drupal=6
Drupal Drupal=6-beta1
Drupal Drupal=6.0
Drupal Drupal=6.0-beta1
Drupal Drupal=6.0-beta2
Drupal Drupal=6.0-beta3
Drupal Drupal=6.0-beta4
Drupal Drupal=6.0-rc-1
Drupal Drupal=6.0-rc-2
Drupal Drupal=6.0-rc-3
Drupal Drupal=6.0-rc-4
Drupal Drupal=6.1
Drupal Drupal=6.2
Drupal Drupal=6.3
Drupal Drupal=6.4
Drupal Drupal=6.5
Drupal Drupal=6.6
Drupal Drupal=6.7
Drupal Drupal=6.8
Drupal Drupal=6.9
Drupal Drupal=6.10
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 6, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1575?
CVE-2009-1575 is considered a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2009-1575?
To fix CVE-2009-1575, update Drupal to version 5.17 or 6.11 or later.
3
What software versions are affected by CVE-2009-1575?
CVE-2009-1575 affects Drupal versions 5.x before 5.17 and 6.x before 6.11.
4
Can CVE-2009-1575 be exploited remotely?
Yes, CVE-2009-1575 can be exploited remotely, allowing attackers to inject arbitrary web script or HTML.
5
What type of vulnerability is CVE-2009-1575 classified as?
CVE-2009-1575 is classified as a cross-site scripting (XSS) vulnerability.