CVE-2009-2372

Publication date 8 July 2009

Last updated 24 July 2024


Ubuntu priority

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
drupal6 9.04 jaunty
Fixed 6.10-1ubuntu0.1
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

SA-CORE-2009-007