FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-4370

This CVE name corresponds to:

Entered Topic
2009-12-25 drupal -- multiple cross-site scripting

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-4370
Phase Assigned(20091221)

Description

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

References

Source Reference
CONFIRM http://drupal.org/files/sa-core-2009-009/SA-CORE-2009-009-6.14.patch
CONFIRM http://drupal.org/node/661586
BID 37372
SECUNIA 37815
XF drupal-menu-xss(54872)