3.5
CVSSv2

CVE-2009-2074

Published: 16/06/2009 Updated: 14/02/2024
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Nodequeue 5.x prior to 5.x-2.7 and 6.x prior to 6.x-2.2, a module for Drupal, allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via vocabulary names.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal nodequeue 5.x-2.0-rc

drupal nodequeue 5.x-2.0_beta

drupal nodequeue 5.x-2.0_rc1

drupal nodequeue 5.x-2.1

drupal nodequeue 5.x-2.2

drupal nodequeue 5.x-2.3

drupal nodequeue 5.x-2.4

drupal nodequeue 5.x-2.5

drupal nodequeue 5.x-2.6

drupal nodequeue 6.x-2.0

drupal nodequeue 6.x-2.0-rc1

drupal nodequeue 6.x-2.0-rc2

drupal nodequeue 6.x-2.1