CVE-2009-1342
20.04.2009, 14:30
Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.
Vendor | Product | Version |
---|---|---|
drupal | cck_comment_reference | 6.x:x |
drupal | cck_comment_reference | 6.x-1.1:x |
𝑥
= Vulnerable software versions
References