CVE-2009-0817
Summary
| CVE | CVE-2009-0817 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-03-05 02:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Drupal | Drupal | All | All | All | All |
| Application | Drupal | Protected Node Module | 5.x | All | All | All |
| Application | Drupal | Protected Node Module | 5.x-1.0 | All | All | All |
| Application | Drupal | Protected Node Module | 5.x-1.2 | All | All | All |
| Application | Drupal | Protected Node Module | 5.x-1.3 | All | All | All |
| Application | Drupal | Protected Node Module | 5.x-1.x-dev | All | All | All |
| Application | Drupal | Protected Node Module | 6.x-1.0 | All | All | All |
| Application | Drupal | Protected Node Module | 6.x-1.2 | All | All | All |
| Application | Drupal | Protected Node Module | 6.x-1.3 | All | All | All |
| Application | Drupal | Protected Node Module | 6.x-1.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/52300 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Unfiltered input bug | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Exploit, Vendor Advisory |
| Drupal Protected Node Module Script Insertion Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Drupal Protected Node Module XSS | Linux/Apache/MySQL/PHP Security | af854a3a-2127-422b-91ae-364da2661108 | lampsecurity.org | Exploit, URL Repurposed |
| protected_node 5.x-1.4 | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch, Vendor Advisory |
| protected_node 6.x-1.5 | drupal.org | af854a3a-2127-422b-91ae-364da2661108 | drupal.org | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.