1 results (0.001 seconds)
CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

CVE-2009-3917
https://notcve.org/view.php?id=CVE-2009-3917
09 Nov 2009 — Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an unspecified field that is copied to the HTML HEAD element. Una vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en el módulo de Drupal "S5 Presentation Player" v6.x-1.x antes de v6.x-1.1, permite a atacantes remotos inyectar HTML o scripts web a través de un campo sin especificar que se copia el elemento ... • http://drupal.org/node/623508 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •