// For flags

CVE-2009-1844

 

Severity Score

3.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6 and 7, which are not properly handled in the "HTML exports of books" feature; and (2) allow remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via the help text of an arbitrary vocabulary. NOTE: vector 1 exists because of an incomplete fix for CVE-2009-1575.

Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados(XSS) en Drupal v5.x anteriores a v5.18 y v6.x anteriores a v6.12 permite (1) a usuarios remotos autenticados inyectar secuencias de comandos web o HTML de su elección a través de secuencias UTF de 8 bytes que son tratadas como UTF 7 bytes por Internet Explorer 6 y 7, ya que no son manejadas de forma adecuada por la característica "HTML exports of books"; y (2) permite a usuarios remotos autenticados con una taxonomía de permisos de administrador, inyectar inyectar secuencias de comandos web o HTML de su elección a través del texto de ayuda de un vocabulario de su elección. NOTA: El vector (1) existe, debido a una solucion incompleta de la CVE-2009-1575.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-06-01 CVE Reserved
  • 2009-06-01 CVE Published
  • 2023-07-20 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.0
Search vendor "Drupal" for product "Drupal" and version "5.0"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.1
Search vendor "Drupal" for product "Drupal" and version "5.1"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.2
Search vendor "Drupal" for product "Drupal" and version "5.2"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.3
Search vendor "Drupal" for product "Drupal" and version "5.3"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.4
Search vendor "Drupal" for product "Drupal" and version "5.4"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.5
Search vendor "Drupal" for product "Drupal" and version "5.5"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.6
Search vendor "Drupal" for product "Drupal" and version "5.6"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.7
Search vendor "Drupal" for product "Drupal" and version "5.7"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.8
Search vendor "Drupal" for product "Drupal" and version "5.8"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.9
Search vendor "Drupal" for product "Drupal" and version "5.9"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.10
Search vendor "Drupal" for product "Drupal" and version "5.10"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.11
Search vendor "Drupal" for product "Drupal" and version "5.11"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.12
Search vendor "Drupal" for product "Drupal" and version "5.12"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.13
Search vendor "Drupal" for product "Drupal" and version "5.13"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.14
Search vendor "Drupal" for product "Drupal" and version "5.14"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.15
Search vendor "Drupal" for product "Drupal" and version "5.15"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
5.16
Search vendor "Drupal" for product "Drupal" and version "5.16"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.0
Search vendor "Drupal" for product "Drupal" and version "6.0"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.1
Search vendor "Drupal" for product "Drupal" and version "6.1"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.2
Search vendor "Drupal" for product "Drupal" and version "6.2"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.3
Search vendor "Drupal" for product "Drupal" and version "6.3"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.4
Search vendor "Drupal" for product "Drupal" and version "6.4"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.5
Search vendor "Drupal" for product "Drupal" and version "6.5"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.6
Search vendor "Drupal" for product "Drupal" and version "6.6"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.7
Search vendor "Drupal" for product "Drupal" and version "6.7"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.8
Search vendor "Drupal" for product "Drupal" and version "6.8"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.9
Search vendor "Drupal" for product "Drupal" and version "6.9"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.10
Search vendor "Drupal" for product "Drupal" and version "6.10"
-
Affected
Drupal
Search vendor "Drupal"
Drupal
Search vendor "Drupal" for product "Drupal"
6.11
Search vendor "Drupal" for product "Drupal" and version "6.11"
-
Affected