CVE-2007-5621

Drupal Asin Field Module < 1.4 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

Scores

EPSS 0.0018
EPSS Percentile 38.8%

Classification

CWE
CWE-79
Status draft

Affected Products (13)

drupal/asin_field_module
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/e-commerce_module
drupal/fullname_field_for_cck
drupal/invite_module
drupal/node_relativity_module
drupal/pathauto_module
drupal/paypal_node_module
drupal/token_module < 1.4
drupal/ubercart_module

Timeline

Published Oct 22, 2007
Tracked Since Feb 18, 2026