Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-1069
Description:Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.
Test IDs: 1.3.6.1.4.1.25623.1.0.63816  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-1069
BugTraq ID: 34172
http://www.securityfocus.com/bid/34172
http://osvdb.org/52783
http://osvdb.org/52784
http://secunia.com/advisories/34370
XForce ISS Database: cck-node-user-xss(49317)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49317




© 1998-2025 E-Soft Inc. All rights reserved.