CVE-2007-5621
Drupal Asin Field Module < 1.4 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.
Scores
EPSS
0.0018
EPSS Percentile
38.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (13)
drupal/asin_field_module
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/e-commerce_module
drupal/fullname_field_for_cck
drupal/invite_module
drupal/node_relativity_module
drupal/pathauto_module
drupal/paypal_node_module
drupal/token_module
< 1.4
drupal/ubercart_module
Timeline
Published
Oct 22, 2007
Tracked Since
Feb 18, 2026