Lucene search

K
cve[email protected]CVE-2009-4369
HistoryDec 21, 2009 - 4:30 p.m.

CVE-2009-4369

2009-12-2116:30:00
CWE-79
web.nvd.nist.gov
22
cve-2009-4369
xss
drupal
contact module
remote code injection

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.9%

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with “administer site-wide contact form” permissions to inject arbitrary web script or HTML via the contact category name.

Affected configurations

NVD
Node
drupaldrupalMatch5.0
OR
drupaldrupalMatch5.0beta1
OR
drupaldrupalMatch5.0beta2
OR
drupaldrupalMatch5.0rc1
OR
drupaldrupalMatch5.0rc2
OR
drupaldrupalMatch5.1
OR
drupaldrupalMatch5.2
OR
drupaldrupalMatch5.4
OR
drupaldrupalMatch5.5
OR
drupaldrupalMatch5.6
OR
drupaldrupalMatch5.7
OR
drupaldrupalMatch5.8
OR
drupaldrupalMatch5.9
OR
drupaldrupalMatch5.10
OR
drupaldrupalMatch5.11
OR
drupaldrupalMatch5.12
OR
drupaldrupalMatch5.13
OR
drupaldrupalMatch5.14
OR
drupaldrupalMatch5.15
OR
drupaldrupalMatch5.16
OR
drupaldrupalMatch5.17
OR
drupaldrupalMatch5.18
OR
drupaldrupalMatch5.19
OR
drupaldrupalMatch5.20
OR
drupaldrupalMatch5.xdev
OR
drupaldrupalMatch6.0
OR
drupaldrupalMatch6.0beta1
OR
drupaldrupalMatch6.0beta2
OR
drupaldrupalMatch6.0beta3
OR
drupaldrupalMatch6.0beta4
OR
drupaldrupalMatch6.0rc-1
OR
drupaldrupalMatch6.0rc-2
OR
drupaldrupalMatch6.0rc-3
OR
drupaldrupalMatch6.0rc-4
OR
drupaldrupalMatch6.1
OR
drupaldrupalMatch6.2
OR
drupaldrupalMatch6.3
OR
drupaldrupalMatch6.4
OR
drupaldrupalMatch6.5
OR
drupaldrupalMatch6.6
OR
drupaldrupalMatch6.7
OR
drupaldrupalMatch6.8
OR
drupaldrupalMatch6.9
OR
drupaldrupalMatch6.10
OR
drupaldrupalMatch6.11
OR
drupaldrupalMatch6.12
OR
drupaldrupalMatch6.13
OR
drupaldrupalMatch6.14

3.5 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.9%

Related for CVE-2009-4369