{"api_version":"1","generated_at":"2026-07-23T07:10:49+00:00","cve":"CVE-2008-3218","urls":{"html":"https://cve.report/CVE-2008-3218","api":"https://cve.report/api/cve/CVE-2008-3218.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3218","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3218"},"summary":{"title":"CVE-2008-3218","description":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-18 16:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 8 Update: drupal-5.8-1.fc8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849","name":"https://bugzilla.redhat.com/show_bug.cgi?id=454849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 454849 – drupal: multiple security issues in < 6.3,5.8/5.9 (SA-2008-044,SA-2008-046 - CVE-2008-3218, CVE-2008-3219, CVE-2008-3220, CVE-2008-3221, CVE-2008-3222, CVE-2008-3223)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30168","name":"http://www.securityfocus.com/bid/30168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Drupal Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 9 Update: drupal-6.3-1.fc9","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31079","name":"http://secunia.com/advisories/31079","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Fedora update for drupal - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2008/07/10/3","name":"http://www.openwall.com/lists/oss-security/2008/07/10/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE request: multiple drupal issues in < 6.3,5.8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43704","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43704","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/280571","name":"http://drupal.org/node/280571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SA-2008-044 - Drupal core - Multiple vulnerabilities | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 8 Update: drupal-5.9-1.fc8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3218","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3218","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3218","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3218","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3218","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2008-3218","qid":"690343","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for drupal (ecedde1c-5128-11dd-a4e1-0030843d3802)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:28:41.657Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"30168","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30168"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/280571"},{"name":"drupal-taxonomyterms-xss(43704)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43704"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849"},{"name":"FEDORA-2008-6916","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html"},{"name":"31079","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31079"},{"name":"FEDORA-2008-6415","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html"},{"name":"[oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2008/07/10/3"},{"name":"FEDORA-2008-6411","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"30168","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30168"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/280571"},{"name":"drupal-taxonomyterms-xss(43704)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43704"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849"},{"name":"FEDORA-2008-6916","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html"},{"name":"31079","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31079"},{"name":"FEDORA-2008-6415","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html"},{"name":"[oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2008/07/10/3"},{"name":"FEDORA-2008-6411","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3218","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"30168","refsource":"BID","url":"http://www.securityfocus.com/bid/30168"},{"name":"http://drupal.org/node/280571","refsource":"CONFIRM","url":"http://drupal.org/node/280571"},{"name":"drupal-taxonomyterms-xss(43704)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43704"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=454849","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849"},{"name":"FEDORA-2008-6916","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html"},{"name":"31079","refsource":"SECUNIA","url":"http://secunia.com/advisories/31079"},{"name":"FEDORA-2008-6415","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html"},{"name":"[oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2008/07/10/3"},{"name":"FEDORA-2008-6411","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3218","datePublished":"2008-07-18T16:00:00.000Z","dateReserved":"2008-07-18T00:00:00.000Z","dateUpdated":"2024-08-07T09:28:41.657Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-18 16:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.3","matchCriteriaId":"F2B32D57-2123-41FB-9594-AF40304999A9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*","matchCriteriaId":"72E4DB7F-07C3-46BB-AAA2-05CD0312C57F"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*","matchCriteriaId":"743CBBB1-C140-4FEF-B40E-FAE4511B1140"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3218","Ordinal":"1","Title":"CVE-2008-3218","CVE":"CVE-2008-3218","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3218","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.","Type":"Description","Title":"CVE-2008-3218"},{"CveYear":"2008","CveId":"3218","Ordinal":"2","NoteData":"2008-07-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3218","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}