![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2008-6170 |
Description: | Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.61800 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-6170 BugTraq ID: 31882 http://www.securityfocus.com/bid/31882 https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00783.html https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00826.html http://secunia.com/advisories/32297 http://secunia.com/advisories/32441 http://www.vupen.com/english/advisories/2008/2913 XForce ISS Database: drupal-book-page-xss(46052) https://exchange.xforce.ibmcloud.com/vulnerabilities/46052 |