CVE-2009-0817
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo Protected Node v5.x anterior v5.x-1.4 y v6.x anterior a v6.x-1.5 para Drupal, permite a usuarios autenticados remotamente con permisos de "configuración administrativa del sitio", la inyección de secuencias de comandos web o HTML de su elección a través del campo Password Page Info, que no está manejado adecuadamente por la función protected_node_enterpassword en protected_node.module.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-03-04 CVE Reserved
- 2009-03-05 CVE Published
- 2024-02-15 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/52300 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48980 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://drupal.org/node/385950 | 2024-08-07 | |
http://lampsecurity.org/node/28 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://drupal.org/node/386604 | 2024-02-14 | |
http://drupal.org/node/386606 | 2024-02-14 | |
http://www.vupen.com/english/advisories/2009/0572 | 2024-02-14 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/34060 | 2024-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 5.x Search vendor "Drupal" for product "Protected Node Module" and version "5.x" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 5.x-1.0 Search vendor "Drupal" for product "Protected Node Module" and version "5.x-1.0" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 5.x-1.2 Search vendor "Drupal" for product "Protected Node Module" and version "5.x-1.2" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 5.x-1.3 Search vendor "Drupal" for product "Protected Node Module" and version "5.x-1.3" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 5.x-1.x-dev Search vendor "Drupal" for product "Protected Node Module" and version "5.x-1.x-dev" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 6.x-1.0 Search vendor "Drupal" for product "Protected Node Module" and version "6.x-1.0" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 6.x-1.2 Search vendor "Drupal" for product "Protected Node Module" and version "6.x-1.2" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 6.x-1.3 Search vendor "Drupal" for product "Protected Node Module" and version "6.x-1.3" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|
Drupal Search vendor "Drupal" | Protected Node Module Search vendor "Drupal" for product "Protected Node Module" | 6.x-1.4 Search vendor "Drupal" for product "Protected Node Module" and version "6.x-1.4" | - |
Affected
| in | Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | * | - |
Safe
|