Vulnerability Name: | CVE-2008-3218 (CCN-43704) | ||||||||
Assigned: | 2008-07-09 | ||||||||
Published: | 2008-07-09 | ||||||||
Updated: | 2021-04-19 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-3218 Source: CCN Type: DRUPAL-SA-2008-044 Drupal core - Multiple vulnerabilities Source: CONFIRM Type: Vendor Advisory http://drupal.org/node/280571 Source: CCN Type: SA31028 Drupal Multiple Vulnerabilities Source: SECUNIA Type: Third Party Advisory 31079 Source: CCN Type: SourceForge.net: Files vbDrupal, File Release Notes and Changelog, Release Name: 5.8.0 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8 Source: CCN Type: OSVDB ID: 46940 Drupal Free Tagging Taxonomy Terms XSS Source: CCN Type: OSVDB ID: 46941 Drupal OpenID Providers Values XSS Source: BID Type: Third Party Advisory, VDB Entry 30168 Source: CCN Type: BID-30168 Drupal Multiple Remote Vulnerabilities Source: CCN Type: vbDrupal Web site vbDrupal | The best CMS combined with the most popular forum Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=454849 Source: XF Type: Third Party Advisory, VDB Entry drupal-taxonomyterms-xss(43704) Source: XF Type: UNKNOWN drupal-taxonomyterms-xss(43704) Source: FEDORA Type: Third Party Advisory FEDORA-2008-6916 Source: FEDORA Type: Third Party Advisory FEDORA-2008-6415 Source: FEDORA Type: Third Party Advisory FEDORA-2008-6411 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||
BACK |