First published: Tue Jun 16 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via (1) vocabulary names, (2) synonyms, and (3) term names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Drupal | ||
Any of | ||
Drupal Taxonomy Manager | =5.x-1.0 | |
Drupal Taxonomy Manager | =5.x-1.1 | |
Drupal Taxonomy Manager | =6.x-1.0 | |
Drupal Taxonomy Manager | =6.x-1.0-beta1 | |
Drupal Taxonomy Manager | =6.x-1.0-beta2 | |
Drupal | ||
Drupal Taxonomy Manager | =5.x-1.0 | |
Drupal Taxonomy Manager | =5.x-1.1 | |
Drupal Taxonomy Manager | =6.x-1.0 | |
Drupal Taxonomy Manager | =6.x-1.0-beta1 | |
Drupal Taxonomy Manager | =6.x-1.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2079 is a moderate severity cross-site scripting (XSS) vulnerability affecting the Taxonomy Manager module in Drupal.
To resolve CVE-2009-2079, upgrade the Taxonomy Manager module to version 5.x-1.2 or 6.x-1.1 or later.
CVE-2009-2079 affects remote authenticated users with administer taxonomy privileges or those who can add taxonomy terms.
CVE-2009-2079 impacts Taxonomy Manager versions 5.x-1.0, 5.x-1.1 and 6.x-1.0, including beta versions prior to 6.x-1.1.
CVE-2009-2079 is categorized as a cross-site scripting (XSS) vulnerability.