CVE-2009-3917

Drupal S5 Presentation Player <6.x-1.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an unspecified field that is copied to the HTML HEAD element.

Scores

EPSS 0.0032
EPSS Percentile 54.6%

Classification

CWE
CWE-79
Status published

Affected Products (3)

greg_knaddison/s5
greg_knaddison/s5
n/a/n/a

Timeline

Published Nov 09, 2009
Tracked Since Feb 18, 2026