CVE-2008-3219
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
18/07/2008
Last modified:
09/04/2025
Description
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 5.0 (including) | 5.8 (excluding) |
| cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | 6.0 (including) | 6.3 (excluding) |
| cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://drupal.org/node/280571
- http://secunia.com/advisories/31079
- http://www.openwall.com/lists/oss-security/2008/07/10/3
- http://www.securityfocus.com/bid/30168
- https://bugzilla.redhat.com/show_bug.cgi?id=454849
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43701
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html
- http://drupal.org/node/280571
- http://secunia.com/advisories/31079
- http://www.openwall.com/lists/oss-security/2008/07/10/3
- http://www.securityfocus.com/bid/30168
- https://bugzilla.redhat.com/show_bug.cgi?id=454849
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43701
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html



