CVE-2009-2078
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/06/2009
Last modified:
09/04/2025
Description
Multiple cross-site scripting (XSS) vulnerabilities in Booktree 5.x before 5.x-7.3 and 6.x before 6.x-1.1, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) node title and (2) node body in a tree root page.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-1.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-1.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-1.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-1.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-1.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-1.x:dev:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:5.x-7.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:6.x-1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:heine.familiedeelstra:booktree:6.x-1.x:dev:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://drupal.org/node/487810
- http://drupal.org/node/487812
- http://drupal.org/node/487828
- http://secunia.com/advisories/35421
- http://www.securityfocus.com/bid/35287
- http://drupal.org/node/487810
- http://drupal.org/node/487812
- http://drupal.org/node/487828
- http://secunia.com/advisories/35421
- http://www.securityfocus.com/bid/35287