Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3648 to the following vulnerability: Name: CVE-2009-3648 URL: http://cve.mitre.org /cgi-bin/cvename.cgi?name=CVE-2009-3648 Assigned: 20091009 Reference: MISC: https://www.madirish.net/ Reference: BID:36584 Reference: URL: Reference: XF:servicelinks-content-type- xss(53633) Reference: URL: Cross- site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names. Checked drupal-service_links in CVS and this affects Fedora 10, 11, and rawhide.

Fedora 11 Update: drupal-service_links-6.x.1.0-5.fc11

October 13, 2009
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-10466
2009-10-14 00:47:15
--------...

Summary

Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3648 to the following vulnerability: Name: CVE-2009-3648 URL: http://cve.mitre.org /cgi-bin/cvename.cgi?name=CVE-2009-3648 Assigned: 20091009 Reference: MISC: https://www.madirish.net/ Reference: BID:36584 Reference: URL: Reference: XF:servicelinks-content-type- xss(53633) Reference: URL: Cross- site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names. Checked drupal-service_links in CVS and this affects Fedora 10, 11, and rawhide.

Change Log

References

Update Instructions

Severity

Related News