CVE-2009-4369

Publication date 21 December 2009

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with “administer site-wide contact form” permissions to inject arbitrary web script or HTML via the contact category name.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
drupal5 9.10 karmic
Fixed 5.18-1.1ubuntu2.1
9.04 jaunty
Fixed 5.15-1ubuntu1.2
8.10 intrepid
Fixed 5.10-1ubuntu1.1
8.04 LTS hardy
Fixed 5.7-1ubuntu1.2
6.06 LTS dapper Not in release
drupal6 9.10 karmic
Fixed 6.12-1.1ubuntu1.1
9.04 jaunty
Fixed 6.10-1ubuntu0.2
8.10 intrepid Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release