Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.3%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2009-4370
  • Drupal » Drupal » Version: 6.0
    cpe:2.3:a:drupal:drupal:6.0
  • Drupal » Drupal » Version: 6.1
    cpe:2.3:a:drupal:drupal:6.1
  • Drupal » Drupal » Version: 6.10
    cpe:2.3:a:drupal:drupal:6.10
  • Drupal » Drupal » Version: 6.11
    cpe:2.3:a:drupal:drupal:6.11
  • Drupal » Drupal » Version: 6.12
    cpe:2.3:a:drupal:drupal:6.12
  • Drupal » Drupal » Version: 6.13
    cpe:2.3:a:drupal:drupal:6.13
  • Drupal » Drupal » Version: 6.14
    cpe:2.3:a:drupal:drupal:6.14
  • Drupal » Drupal » Version: 6.2
    cpe:2.3:a:drupal:drupal:6.2
  • Drupal » Drupal » Version: 6.3
    cpe:2.3:a:drupal:drupal:6.3
  • Drupal » Drupal » Version: 6.4
    cpe:2.3:a:drupal:drupal:6.4
  • Drupal » Drupal » Version: 6.5
    cpe:2.3:a:drupal:drupal:6.5
  • Drupal » Drupal » Version: 6.6
    cpe:2.3:a:drupal:drupal:6.6
  • Drupal » Drupal » Version: 6.7
    cpe:2.3:a:drupal:drupal:6.7
  • Drupal » Drupal » Version: 6.8
    cpe:2.3:a:drupal:drupal:6.8
  • Drupal » Drupal » Version: 6.9
    cpe:2.3:a:drupal:drupal:6.9


Contact Us

Shodan ® - All rights reserved