Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-02-19T15:02:00
Updated: 2024-08-07T11:20:25.475Z
Reserved: 2009-02-19T00:00:00
Link: CVE-2008-6170
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-02-19T15:30:00.420
Modified: 2024-11-21T00:55:50.980
Link: CVE-2008-6170
Redhat
No data.