CVE-2009-4042
Published Nov 20, 2009
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB81E6D3-CB1E-4DCB-935E-C966EE3AEBC1" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:alpha_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBD84388-C503-4AEA-87FD-1E2FEBC29110" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:alpha_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8BA0887-6EA3-490A-8F88-14B0343B66EB" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:beta_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8D018DA-69F0-4B0E-96A1-2A77DDB45FFA" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:beta_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "209B97DD-6013-4F03-8E84-95A8159DCF2A" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:rc_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9BED77F-51A3-40C9-83DE-744E734190B9" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:rc_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C603A91-AEB6-435D-B54F-0EF0FFE0CB0B" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:rc_3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9426C5E-77C4-42F6-AB21-C33014B4D0E5" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:rc_4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2971E171-312A-47E0-A862-A1D4522C5A8C" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.0:rc_5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72BC1438-EC5F-4539-AEFE-F1D9514929D9" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "787DA539-DBE6-4010-8266-11D8646742D9" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D82E704-290B-4629-AF9E-7674A2203F9C" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E256B411-730D-4356-98DA-D1706DF2AB3F" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67543F6C-6349-43F4-996B-27CB19119426" }, { "criteria": "cpe:2.3:a:marek_sotak:rootcandy:6.x-1.x:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A79488D-E370-4229-8F62-94B02A57B496" } ], "operator": "OR" } ], "operator": "AND" } ]