CVE-2008-3219
Last modified
CVE-2008-3219 is a vulnerability of currently unknown severity. The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Drupal | >= 5.0, < 5.8 |
| Drupal | Drupal | >= 6.0, < 6.3 |
| Fedoraproject | Fedora | 8 |
| Fedoraproject | Fedora | 9 |
References
- http://drupal.org/node/280571Patch, Vendor Advisory
- http://secunia.com/advisories/31079Third Party Advisory
- http://www.openwall.com/lists/oss-security/2008/07/10/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/30168Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=454849Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43701Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.htmlThird Party Advisory
- http://drupal.org/node/280571Patch, Vendor Advisory
- http://secunia.com/advisories/31079Third Party Advisory
- http://www.openwall.com/lists/oss-security/2008/07/10/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/30168Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=454849Issue Tracking, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43701Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3219?
How severe is CVE-2008-3219?
How do I fix CVE-2008-3219?
Are you affected by CVE-2008-3219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
