Vulnerability Name: | CVE-2008-3219 (CCN-43701) | ||||||||
Assigned: | 2008-07-09 | ||||||||
Published: | 2008-07-09 | ||||||||
Updated: | 2021-04-15 | ||||||||
Summary: | The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-3219 Source: CCN Type: DRUPAL-SA-2008-044 Drupal core - Multiple vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory http://drupal.org/node/280571 Source: CCN Type: DRUPAL-SA-2008-045 OpenID - Multiple vulnerabilities Source: CCN Type: SA31027 Drupal OpenID Module Vulnerabilities Source: SECUNIA Type: Third Party Advisory 31079 Source: CCN Type: SourceForge.net: Files vbDrupal, File Release Notes and Changelog, Release Name: 5.8.0 Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8 Source: CCN Type: OSVDB ID: 46942 Drupal filter_xss_admin() Function Administrator Input HTML Object XSS Source: CCN Type: BID-30165 Drupal OpenID Module Cross Site Scripting and Request Forgery Vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 30168 Source: CCN Type: BID-30168 Drupal Multiple Remote Vulnerabilities Source: CCN Type: vbDrupal Web site vbDrupal | The best CMS combined with the most popular forum Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=454849 Source: XF Type: Third Party Advisory, VDB Entry openid-unspecified-xss(43701) Source: XF Type: UNKNOWN openid-unspecified-xss(43701) Source: FEDORA Type: Third Party Advisory FEDORA-2008-6916 Source: FEDORA Type: Third Party Advisory FEDORA-2008-6415 Source: FEDORA Type: Third Party Advisory FEDORA-2008-6411 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
BACK |