CVE-2008-6972
Karen Stevenson Cck - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.
References (5)
Scores
EPSS
0.0016
EPSS Percentile
36.2%
Classification
CWE
CWE-79
Status
published
Affected Products (12)
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
yves_chedemois/cck
yves_chedemois/cck
yves_chedemois/cck
yves_chedemois/cck
yves_chedemois/cck
n/a/n/a
Timeline
Published
Aug 13, 2009
Tracked Since
Feb 18, 2026