← Back

CVE-2007-5621

nvd nist
Published: Oct 22, 2007Modified: Apr 23, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

Affected (14)

10 products
Asin Field Module
Drupal
E Commerce Module
Fullname Field For Cck
Invite Module
Node Relativity Module
Pathauto Module
Paypal Node Module
Token Module
Ubercart Module
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Drupal
Version 4.7
Version 5.0
Version 5.1
Version 5.2
All versions
All versions
All versions
All versions
All versions
All versions
Drupal
Up to 1.4
Up to 1.8
All versions

References (8)

Source: cve@mitre.org
Patch
Source: cve@mitre.org
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.