CVE-2008-6170

Drupal - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.

Scores

EPSS 0.0024
EPSS Percentile 47.4%

Classification

CWE
CWE-79
Status published

Affected Products (19)

drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 4 more

Timeline

Published Feb 19, 2009
Tracked Since Feb 18, 2026