Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2009-02-19T15:02:00
Updated: 2024-08-07T11:20:25.475Z
Reserved: 2009-02-19T00:00:00
Link: CVE-2008-6170

No data.

Status : Deferred
Published: 2009-02-19T15:30:00.420
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-6170

No data.