4.3
CVSSv2

CVE-2009-3435

Published: 28/09/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x prior to 5.x-1.2 and 6.x prior to 6.x-1.18, a module for Drupal, allows remote malicious users to inject arbitrary web script or HTML via a variable name.

Vulnerable Product Search on Vulmon Subscribe to Product

moshe_weitzman devel 5.x-1.x-dev

moshe_weitzman devel 6.x-1.0

moshe_weitzman devel 6.x-1.1

moshe_weitzman devel 6.x-1.2

moshe_weitzman devel 6.x-1.9

moshe_weitzman devel 6.x-1.10

moshe_weitzman devel 6.x-1.17

moshe_weitzman devel 6.x-1.x-dev

moshe_weitzman devel 5.x-0.3

moshe_weitzman devel 5.x-0.4

moshe_weitzman devel 6.x-1.5

moshe_weitzman devel 6.x-1.6

moshe_weitzman devel 6.x-1.13

moshe_weitzman devel 6.x-1.14

moshe_weitzman devel 5.x-1.0

moshe_weitzman devel 5.x-1.1

moshe_weitzman devel 6.x-1.7

moshe_weitzman devel 6.x-1.8

moshe_weitzman devel 6.x-1.15

moshe_weitzman devel 6.x-1.16

moshe_weitzman devel 5.x-0.1

moshe_weitzman devel 5.x-0.2

moshe_weitzman devel 6.x-1.3

moshe_weitzman devel 6.x-1.4

moshe_weitzman devel 6.x-1.11

moshe_weitzman devel 6.x-1.12