Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-4532

EPSS 0.26% · P49
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-4532

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform creation privileges, to inject arbitrary web script or HTML via a field label.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Drupal Webform模块跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Drupal的Webform模块中存在跨站脚本攻击漏洞。拥有webform特定特权的远程认证用户可以借助字段标签,注入任意的web脚本或HTML。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-4532

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-4532

Please Login to view more intelligence information

Same Patch Batch · n/a · 2009-12-31 · 29 CVEs total

CVE-2009-4526Drupal Printer e-mail和PDF version模块安全绕过漏洞
CVE-2009-4502Zabbix Agent NET_TCP_LISTEN函数权限许可和安全绕过漏洞
CVE-2009-4501Zabbix Server 'str.c' zbx_get_next_field函数拒绝服务漏洞
CVE-2009-4500zabbix 'trapper.c' 空指针拒绝服务漏洞
CVE-2009-4499Zabbix 'get_history_lastid()' SQL注入漏洞
CVE-2009-4498Zabbix 操作系统命令注入漏洞
CVE-2009-4535valenok mongoose 信息泄露漏洞
CVE-2009-4534Drupal FAQ Ask模块URI开放重定向漏洞
CVE-2009-4533Drupal Webform模块未明会话变量漏洞
CVE-2009-4531jazu100 httpdx URI信息泄露漏洞
CVE-2009-4530valenok mongoose 附录::$DATA到URI信息泄露漏洞
CVE-2009-4529Intervations NaviCOPA Web Server HTTP请求源码泄露漏洞
CVE-2009-4528Drupal Organic Groups Vocabulary 模块未授权访问漏洞
CVE-2009-4527Niif Shibboleth验证模块身份认证绕过漏洞
CVE-2009-4512Indymedia oscailt 'index.php'目录遍历漏洞
CVE-2009-4525Drupal Printer e-mail和PDF version 模块特制数据HTML注入漏洞
CVE-2009-4524Drupal RealName 模块跨站脚本攻击漏洞
CVE-2009-4523Zainu 'index.php' SearchSong跨站脚本攻击漏洞
CVE-2009-4522bloofoxCMS 'index.php' search跨站脚本攻击漏洞
CVE-2009-4521Eclipse Business Intelligence和Reporting Tools birt-viewer/run跨站脚本攻击漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-4532

No comments yet


Leave a comment