CVE-2009-3156
Published Sep 10, 2009
Last updated 9 months ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:N/AC:H/Au:S/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-1.0-beta:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0415C2C-C9BB-4DD6-B827-C140B2EB08B1" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-1.x-dev:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47962BD0-9938-4DF4-AA83-FC36E962EE6B" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3F26B0B-F3C3-45BF-90F8-0F3EAB5F2C17" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB57869E-0886-4770-B26B-E1D8542B5C9C" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C5BDB03-7356-4522-BD20-6322D726EDD5" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77038900-2F18-42E7-8E45-7C1A7E3AE1B8" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A922CA8F-2AAD-4842-9887-D3D4BCE6868C" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:rc5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "17BA84A3-E818-482F-9B33-32C709BFE21B" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0:rc6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA0D09CD-F116-4186-9F60-EC44AB22CA55" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0-beta:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34871D3D-233B-41C6-8A74-F93A5C640D42" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0-beta2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69506981-E5A4-4089-BF94-509A5F005CB3" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0-beta3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A78FE81-E49F-4766-BB8F-6253D0B56ADA" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.0-beta4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFE3BF49-9D2B-4182-BBA9-A491A2F89AD0" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20844EE0-6771-45FE-8B4E-AA9462488F3A" }, { "criteria": "cpe:2.3:a:karen_stevenson:date:6.x-2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4DF0E66-9076-4535-B42E-326A9A6C0D7F" } ], "operator": "OR" } ], "operator": "AND" } ]