CVE-2009-0603
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the…
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- drupal/link module
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0036.html
- http://osvdb.org/51780
- http://secunia.com/advisories/33835Vendor Advisory
- http://www.securityfocus.com/bid/33642
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48553
- http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0036.html
- http://osvdb.org/51780
- http://secunia.com/advisories/33835Vendor Advisory
- http://www.securityfocus.com/bid/33642
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48553
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.