{"api_version":"1","generated_at":"2026-07-23T12:02:25+00:00","cve":"CVE-2008-0274","urls":{"html":"https://cve.report/CVE-2008-0274","api":"https://cve.report/api/cve/CVE-2008-0274.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0274","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0274"},"summary":{"title":"CVE-2008-0274","description":"Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-01-15 20:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vbdrupal.org/forum/showthread.php?t=1349","name":"http://www.vbdrupal.org/forum/showthread.php?t=1349","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"vbDrupal 5.6.0 released - vbDrupal Forums","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39605","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39605","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/208565","name":"http://drupal.org/node/208565","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SA-2008-007 - Drupal core - Cross site scripting (register_globals) | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27238","name":"http://www.securityfocus.com/bid/27238","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Drupal Prior To 4.7.11 and 5.6 Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2008/0127","name":"http://www.vupen.com/english/advisories/2008/0127","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0134","name":"http://www.vupen.com/english/advisories/2008/0134","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28486","name":"http://secunia.com/advisories/28486","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"vbDrupal Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28422","name":"http://secunia.com/advisories/28422","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Drupal Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vbdrupal.org/forum/showthread.php?p=6878","name":"http://www.vbdrupal.org/forum/showthread.php?p=6878","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"vbDrupal 4.7.11.0 released - vbDrupal Forums","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0274","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0274","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"274","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"274","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:39:35.173Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-0134","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0134"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vbdrupal.org/forum/showthread.php?p=6878"},{"name":"27238","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27238"},{"name":"28422","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28422"},{"name":"drupal-theme-xss(39605)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39605"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/208565"},{"name":"ADV-2008-0127","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0127"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vbdrupal.org/forum/showthread.php?t=1349"},{"name":"28486","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28486"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-0134","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0134"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vbdrupal.org/forum/showthread.php?p=6878"},{"name":"27238","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27238"},{"name":"28422","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28422"},{"name":"drupal-theme-xss(39605)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39605"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/208565"},{"name":"ADV-2008-0127","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0127"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vbdrupal.org/forum/showthread.php?t=1349"},{"name":"28486","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28486"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0274","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-0134","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0134"},{"name":"http://www.vbdrupal.org/forum/showthread.php?p=6878","refsource":"CONFIRM","url":"http://www.vbdrupal.org/forum/showthread.php?p=6878"},{"name":"27238","refsource":"BID","url":"http://www.securityfocus.com/bid/27238"},{"name":"28422","refsource":"SECUNIA","url":"http://secunia.com/advisories/28422"},{"name":"drupal-theme-xss(39605)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39605"},{"name":"http://drupal.org/node/208565","refsource":"CONFIRM","url":"http://drupal.org/node/208565"},{"name":"ADV-2008-0127","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0127"},{"name":"http://www.vbdrupal.org/forum/showthread.php?t=1349","refsource":"CONFIRM","url":"http://www.vbdrupal.org/forum/showthread.php?t=1349"},{"name":"28486","refsource":"SECUNIA","url":"http://secunia.com/advisories/28486"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0274","datePublished":"2008-01-15T19:00:00.000Z","dateReserved":"2008-01-15T00:00:00.000Z","dateUpdated":"2024-08-07T07:39:35.173Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-01-15 20:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:4.7:*:*:*:*:*:*:*","matchCriteriaId":"FFE9A8A9-19D4-4C50-A4B5-2EFD8B05BAE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:5.0:*:*:*:*:*:*:*","matchCriteriaId":"BDBE79A6-5762-4A7C-8FDA-C11FFFDCFC9B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"274","Ordinal":"1","Title":"CVE-2008-0274","CVE":"CVE-2008-0274","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"274","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.","Type":"Description","Title":"CVE-2008-0274"},{"CveYear":"2008","CveId":"274","Ordinal":"2","NoteData":"2008-01-15","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"274","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}