3.5
CVSSv2

CVE-2009-2610

Published: 27/07/2009 Updated: 27/07/2009
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x prior to 5.x-1.13 and 6.x prior to 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.

Vulnerable Product Search on Vulmon Subscribe to Product

scott_courtney links_package 6.x-1.0-beta1

scott_courtney links_package 6.x-1.0-beta2

scott_courtney links_package 6.x-1.0-beta3

scott_courtney links_package 6.x-1.0-beta5

scott_courtney links_package 5.x-1.11

scott_courtney links_package 5.x-1.x-dev

scott_courtney links_package 5.x-1.9

scott_courtney links_package 5.x-1.8

scott_courtney links_package 6.x-1.0-beta11

scott_courtney links_package 6.x-1.0-beta12

scott_courtney links_package 6.x-1.0-beta13

scott_courtney links_package 6.x-1.0-beta14

scott_courtney links_package 5.x-1.12-beta1

scott_courtney links_package 5.x-1.7

scott_courtney links_package 5.x-1.5

scott_courtney links_package 5.x-1.2

scott_courtney links_package 6.x-1.0-beta6

scott_courtney links_package 6.x-1.x-dev

scott_courtney links_package 6.x-1.0

scott_courtney links_package 5.x-1.12

scott_courtney links_package 5.x-1.6

scott_courtney links_package 5.x-1.4

scott_courtney links_package 6.x-1.0-beta7

scott_courtney links_package 6.x-1.0-beta10

scott_courtney links_package 6.x-1.0-beta15

scott_courtney links_package 6.x-1.1