{"api_version":"1","generated_at":"2026-07-23T07:41:06+00:00","cve":"CVE-2008-3219","urls":{"html":"https://cve.report/CVE-2008-3219","api":"https://cve.report/api/cve/CVE-2008-3219.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3219","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3219"},"summary":{"title":"CVE-2008-3219","description":"The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not \"prevent use of the object HTML tag in administrator input,\" which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-18 16:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 8 Update: drupal-5.8-1.fc8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849","name":"https://bugzilla.redhat.com/show_bug.cgi?id=454849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Bug 454849 – drupal: multiple security issues in < 6.3,5.8/5.9 (SA-2008-044,SA-2008-046 - CVE-2008-3218, CVE-2008-3219, CVE-2008-3220, CVE-2008-3221, CVE-2008-3222, CVE-2008-3223)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30168","name":"http://www.securityfocus.com/bid/30168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Drupal Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 9 Update: drupal-6.3-1.fc9","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31079","name":"http://secunia.com/advisories/31079","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Fedora update for drupal - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2008/07/10/3","name":"http://www.openwall.com/lists/oss-security/2008/07/10/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE request: multiple drupal issues in < 6.3,5.8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43701","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43701","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/280571","name":"http://drupal.org/node/280571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SA-2008-044 - Drupal core - Multiple vulnerabilities | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html","name":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 8 Update: drupal-5.9-1.fc8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3219","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3219","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3219","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:28:41.645Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"30168","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30168"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/280571"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849"},{"name":"FEDORA-2008-6916","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html"},{"name":"31079","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31079"},{"name":"FEDORA-2008-6415","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html"},{"name":"[oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2008/07/10/3"},{"name":"FEDORA-2008-6411","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html"},{"name":"openid-unspecified-xss(43701)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43701"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not \"prevent use of the object HTML tag in administrator input,\" which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"30168","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30168"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/280571"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849"},{"name":"FEDORA-2008-6916","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html"},{"name":"31079","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31079"},{"name":"FEDORA-2008-6415","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html"},{"name":"[oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2008/07/10/3"},{"name":"FEDORA-2008-6411","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html"},{"name":"openid-unspecified-xss(43701)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43701"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3219","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not \"prevent use of the object HTML tag in administrator input,\" which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"30168","refsource":"BID","url":"http://www.securityfocus.com/bid/30168"},{"name":"http://drupal.org/node/280571","refsource":"CONFIRM","url":"http://drupal.org/node/280571"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=454849","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=454849"},{"name":"FEDORA-2008-6916","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html"},{"name":"31079","refsource":"SECUNIA","url":"http://secunia.com/advisories/31079"},{"name":"FEDORA-2008-6415","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html"},{"name":"[oss-security] 20080710 CVE request: multiple drupal issues in < 6.3,5.8","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2008/07/10/3"},{"name":"FEDORA-2008-6411","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html"},{"name":"openid-unspecified-xss(43701)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43701"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3219","datePublished":"2008-07-18T16:00:00.000Z","dateReserved":"2008-07-18T00:00:00.000Z","dateUpdated":"2024-08-07T09:28:41.645Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-18 16:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.8","matchCriteriaId":"9FCAF0FC-E4F0-4F58-BEE1-95E6A27CBCAD"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.3","matchCriteriaId":"F2B32D57-2123-41FB-9594-AF40304999A9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*","matchCriteriaId":"72E4DB7F-07C3-46BB-AAA2-05CD0312C57F"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:*","matchCriteriaId":"743CBBB1-C140-4FEF-B40E-FAE4511B1140"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3219","Ordinal":"1","Title":"CVE-2008-3219","CVE":"CVE-2008-3219","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3219","Ordinal":"1","NoteData":"The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not \"prevent use of the object HTML tag in administrator input,\" which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.","Type":"Description","Title":"CVE-2008-3219"},{"CveYear":"2008","CveId":"3219","Ordinal":"2","NoteData":"2008-07-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3219","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}