{ "id": "CVE-2009-1942", "sourceIdentifier": "cve@mitre.org", "published": "2009-06-05T18:30:00.313", "lastModified": "2009-06-08T04:00:00.000", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors." }, { "lang": "es", "value": "Vulnerabilidad de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en el modulo para Drupal, Quiz v5.x, v6.x-2.x anterior a v6.x-2.2, v6.x-3.x anterior a v6.x-3.0, permite a usuarios remotos autenticados con acceso a la creaci\u00f3n de cuestionarios o acceso a las preguntas de los cuestionarios, se podr\u00eda inyectar secuencias de comandos web o HTML a trav\u00e9s de vectores sin especificar." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 3.5 }, "baseSeverity": "LOW", "exploitabilityScore": 6.8, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:5.x:*:*:*:*:*:*:*", "matchCriteriaId": "F1300BA4-0341-40A2-A580-4CEF4D70E930" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.0:*:*:*:*:*:*:*", "matchCriteriaId": "FBAB35A7-147B-4EB2-B5E3-C1A1A205CC1D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.0:alpha1:*:*:*:*:*:*", "matchCriteriaId": "2C6466C8-070E-403D-A44D-4719BCB66ECF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.0:alpha2:*:*:*:*:*:*", "matchCriteriaId": "D18685B6-CC2B-4B82-8523-787E36D0856F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "9D902AFF-0677-4299-9B7E-1082F7ABF979" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.0:rc1:*:*:*:*:*:*", "matchCriteriaId": "A34B6BBC-243C-4BE5-B069-20A2C2F9727C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.0:rc2:*:*:*:*:*:*", "matchCriteriaId": "38A5A7C7-869B-4FCC-A94E-12B3A09D94CF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.1:*:*:*:*:*:*:*", "matchCriteriaId": "55DDDB0A-D9BE-46E6-A26C-E8F88ACC3692" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-2.x:dev:*:*:*:*:*:*", "matchCriteriaId": "6288701C-B559-4EE4-A5B3-48B779A1BD7C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-3.0:*:*:*:*:*:*:*", "matchCriteriaId": "70267A32-8329-417A-967E-8844E6CE6942" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-3.0:alpha1:*:*:*:*:*:*", "matchCriteriaId": "6B51E500-6694-42A4-B3B9-FB15562CBA47" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-3.0:alpha2:*:*:*:*:*:*", "matchCriteriaId": "71A9F973-592A-41D7-AECD-80A633595277" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-3.0:beta1:*:*:*:*:*:*", "matchCriteriaId": "753F8DDB-DF9E-4B4C-9CA1-2A20510D57E7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-3.x:dev:*:*:*:*:*:*", "matchCriteriaId": "C18710D5-4138-4D97-AD0E-68489E4D305F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:drupal:quiz:6.x-3.x:rc2:*:*:*:*:*:*", "matchCriteriaId": "0E62D2DB-67CE-4747-B81C-DF1B8BC6D201" } ] } ] } ], "references": [ { "url": "http://drupal.org/node/481270", "source": "cve@mitre.org", "tags": [ "Patch" ] }, { "url": "http://drupal.org/node/481274", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://drupal.org/node/481308", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/35199", "source": "cve@mitre.org", "tags": [ "Patch" ] } ] }