« Volver al listado

CVE-2009-4429

Estado: ModificadaBaja (3.5)—

Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4429",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-12-28T19:00:00.750",
  "references": [
    {
      "url": "http://drupal.org/node/661404",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37752",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.madirish.net/?article=440",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/61107",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/37371",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54860",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://drupal.org/node/661404",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37752",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.madirish.net/?article=440",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/61107",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/37371",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54860",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with \"administer sections\" privileges to inject arbitrary web script or HTML via a section name (aka the Name field)."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo Sections v5.x anteriores a v5.x-1.3 y v6.x anteriores a v6.x-1.3 para Drupal permite a usuarios autenticados remotamente con privilegios de \"administrar secciones\" inyectar secuencias de comandos web o HTML de su elección mediante un nombre de sección (también conocido como campo \"Name\")."
    }
  ],
  "lastModified": "2026-06-16T23:13:39.087",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:5.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F681C08-596E-4EA4-897E-E6A1BDCE5316"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:5.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EEBAAFF-FF7A-4890-85A0-BF4A8733B644"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:5.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAD92B36-CCAB-4F8F-91E1-40ADF60A9490"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:5.x-1.x-dev:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "947DCA57-3445-4727-8F85-16DE5C9C1B27"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:6.x-1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2159DE60-2546-47A9-B6A6-91E8AB5EF5B2"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:6.x-1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91C956B3-D216-4952-9152-D587F881C6FF"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:6.x-1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "511C853F-60BC-4998-98FF-10B7542F1C7E"
            },
            {
              "criteria": "cpe:2.3:a:alexander_hass:sections_module:6.x-1.x-dev:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A18B209E-3E9A-464F-B3EC-221F66BA2FC9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}