CVE-2009-2372
Publication date 8 July 2009
Last updated 24 July 2024
Ubuntu priority
Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.
Status
Package | Ubuntu Release | Status |
---|---|---|
drupal6 | 9.04 jaunty |
Fixed 6.10-1ubuntu0.1
|
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |