CVE-2009-3488 Information

Share on:

Description

Cross-site scripting (XSS) vulnerability in the Bibliography (aka Biblio) module 6.x-1.6 for Drupal allows remote authenticated users with certain content-creation privileges to inject arbitrary web script or HTML via the Title field probably a different vulnerability than CVE-2009-3479.

Reference

http://seclists.org/fulldisclosure/2009/Sep/0373.html http://secunia.com/advisories/36834 http://www.securityfocus.com/bid/36521 https://exchange.xforce.ibmcloud.com/vulnerabilities/53483