Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | All versions |
| Ticklespace | Answers Module | 5.x-1.x-dev |
Related Weaknesses (CWE)
References
- http://drupal.org/node/310223Vendor Advisory
- http://seclists.org/fulldisclosure/2008/Sep/0202.html
- http://www.securityfocus.com/bid/31146
- http://www.vupen.com/english/advisories/2008/2620Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45112
- http://drupal.org/node/310223Vendor Advisory
- http://seclists.org/fulldisclosure/2008/Sep/0202.html
- http://www.securityfocus.com/bid/31146
- http://www.vupen.com/english/advisories/2008/2620Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45112
FAQ
What is CVE-2008-6413?
CVE-2008-6413 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Si...
How severe is CVE-2008-6413?
CVE-2008-6413 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6413?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Drupal, Ticklespace Answers Module.