« Volver al listado

CVE-2008-6972

Estado: ModificadaBaja (3.5)—

Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-6972",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-13T16:30:01.233",
  "references": [
    {
      "url": "http://drupal.org/node/304093",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/47929",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31757",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/31027",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44915",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/304093",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/47929",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31757",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/31027",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44915",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with \"administer content\" permissions to inject arbitrary web script or HTML via the (1) \"field label,\" (2) \"help text,\" or (3) \"allowed values\" settings."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad múltiple de ejecución de secuencias de comandos en sitios cruzados - XSS - en Drupal Content Construction Kit (CCK) v5.x hasta v5.x-1.8 permite a los usuarios remotos autenticados con permisos \"administrar contenido\" inyectar arbitrariamente una secuencia de comandos web o HTML a través de los parámetros (1) \"field label,\" (2) \"help text,\" o (3) \"allowed values\"."
    }
  ],
  "lastModified": "2026-06-16T23:03:20.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:karen_stevenson:cck:5.x-1.0-beta:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E5BFC44-CC70-4F5A-95DF-2A8B4E7FF901"
            },
            {
              "criteria": "cpe:2.3:a:karen_stevenson:cck:5.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2215B4E1-902D-4589-8F9F-B6314AE52E3A"
            },
            {
              "criteria": "cpe:2.3:a:karen_stevenson:cck:5.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "970B9EFC-00F4-4202-95AF-825A4BF29878"
            },
            {
              "criteria": "cpe:2.3:a:karen_stevenson:cck:5.x-1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25365C2D-66D9-4A50-926B-774B37EE2482"
            },
            {
              "criteria": "cpe:2.3:a:karen_stevenson:cck:5.x-1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74A1E260-E3E5-403B-81BB-490F4324D6D1"
            },
            {
              "criteria": "cpe:2.3:a:karen_stevenson:cck:5.x-1.x-dev:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A7501B8-CFC0-4909-9DAB-0B8E78A9B14E"
            },
            {
              "criteria": "cpe:2.3:a:yves_chedemois:cck:5.x-1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1134889-22DA-4829-B157-AAC47883EFD6"
            },
            {
              "criteria": "cpe:2.3:a:yves_chedemois:cck:5.x-1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32D617BA-6060-4AE8-BF91-EC46D79978A4"
            },
            {
              "criteria": "cpe:2.3:a:yves_chedemois:cck:5.x-1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "687DDBBA-C4C4-4094-B06B-5B1B8C46D2AC"
            },
            {
              "criteria": "cpe:2.3:a:yves_chedemois:cck:5.x-1.6-1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "850E6DE9-2D84-4A2F-BFFE-589FC5563791"
            },
            {
              "criteria": "cpe:2.3:a:yves_chedemois:cck:5.x-1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94A3AD40-AEAF-4FAC-9B72-5F83CD072612"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}