Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Asin Field Module | All versions |
| Drupal | Drupal | 4.7 |
| Drupal | E-Commerce Module | All versions |
| Drupal | Fullname Field For Cck | All versions |
| Drupal | Invite Module | All versions |
| Drupal | Node Relativity Module | All versions |
| Drupal | Pathauto Module | All versions |
| Drupal | Paypal Node Module | All versions |
| Drupal | Token Module | <= 1.4 |
| Drupal | Ubercart Module | All versions |
Related Weaknesses (CWE)
References
- http://drupal.org/node/184336Patch
- http://osvdb.org/38073
- http://secunia.com/advisories/27291Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37275
- http://drupal.org/node/184336Patch
- http://osvdb.org/38073
- http://secunia.com/advisories/27291Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37275
FAQ
What is CVE-2007-5621?
CVE-2007-5621 is a vulnerability with a CVSS score of 3.5 (LOW). Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Nod...
How severe is CVE-2007-5621?
CVE-2007-5621 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5621?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Asin Field Module, Drupal Drupal, Drupal E-Commerce Module, Drupal Fullname Field For Cck, Drupal Invite Module.