CVE-2008-6170
Drupal - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
Scores
EPSS
0.0024
EPSS Percentile
47.4%
Classification
CWE
CWE-79
Status
published
Affected Products (19)
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 4 more
Timeline
Published
Feb 19, 2009
Tracked Since
Feb 18, 2026