Lucene search

K
cve[email protected]CVE-2008-3219
HistoryJul 18, 2008 - 4:41 p.m.

CVE-2008-3219

2008-07-1816:41:00
CWE-79
web.nvd.nist.gov
23
drupal
filter_xss_admin
html tag
administrator input
xss protection
cve-2008-3219
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.3 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.0%

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not “prevent use of the object HTML tag in administrator input,” which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

Affected configurations

NVD
Node
drupaldrupalRange5.05.8
OR
drupaldrupalRange6.06.3
Node
fedoraprojectfedoraMatch8
OR
fedoraprojectfedoraMatch9

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.3 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.0%