Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, allows remote authenticated users, with image-node creation privileges, to inject arbitrary web script or HTML via a node title.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unleashedmind | Img Assist | 5.x-1.0 |
| Drupal | Drupal | All versions |
Related Weaknesses (CWE)
References
- http://drupal.org/node/520564PatchVendor Advisory
- http://osvdb.org/55866
- http://secunia.com/advisories/35879Vendor Advisory
- http://www.securityfocus.com/bid/35710Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51786
- http://drupal.org/node/520564PatchVendor Advisory
- http://osvdb.org/55866
- http://secunia.com/advisories/35879Vendor Advisory
- http://www.securityfocus.com/bid/35710Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51786
FAQ
What is CVE-2009-4557?
CVE-2009-4557 is a vulnerability with a CVSS score of 2.1 (LOW). Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07...
How severe is CVE-2009-4557?
CVE-2009-4557 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4557?
Check the references section above for vendor advisories and patch information. Affected products include: Unleashedmind Img Assist, Drupal Drupal.