CVE-2008-6972

Karen Stevenson Cck - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.

Scores

EPSS 0.0016
EPSS Percentile 36.2%

Classification

CWE
CWE-79
Status published

Affected Products (12)

karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
karen_stevenson/cck
yves_chedemois/cck
yves_chedemois/cck
yves_chedemois/cck
yves_chedemois/cck
yves_chedemois/cck
n/a/n/a

Timeline

Published Aug 13, 2009
Tracked Since Feb 18, 2026