{"api_version":"1","generated_at":"2026-07-23T09:00:11+00:00","cve":"CVE-2009-0817","urls":{"html":"https://cve.report/CVE-2009-0817","api":"https://cve.report/api/cve/CVE-2009-0817.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0817","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0817"},"summary":{"title":"CVE-2009-0817","description":"Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with \"administer site configuration\" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-03-05 02:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48980","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48980","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/52300","name":"http://osvdb.org/52300","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://drupal.org/node/385950","name":"http://drupal.org/node/385950","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Unfiltered input bug | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34060","name":"http://secunia.com/advisories/34060","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Drupal Protected Node Module Script Insertion Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lampsecurity.org/node/28","name":"http://lampsecurity.org/node/28","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","URL Repurposed"],"title":"Drupal Protected Node Module XSS | Linux/Apache/MySQL/PHP Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/386606","name":"http://drupal.org/node/386606","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"protected_node 5.x-1.4 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/386604","name":"http://drupal.org/node/386604","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"protected_node 6.x-1.5 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0572","name":"http://www.vupen.com/english/advisories/2009/0572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0817","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0817","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"817","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"5.x","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"5.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"5.x-1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"5.x-1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"5.x-1.x-dev","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"6.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"6.x-1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"6.x-1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"817","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"protected_node_module","cpe6":"6.x-1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:48:52.319Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/385950"},{"name":"34060","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34060"},{"name":"protectednode-passwordpage-xss(48980)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48980"},{"name":"ADV-2009-0572","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0572"},{"name":"52300","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/52300"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lampsecurity.org/node/28"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/386606"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/386604"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-02-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with \"administer site configuration\" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/385950"},{"name":"34060","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34060"},{"name":"protectednode-passwordpage-xss(48980)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48980"},{"name":"ADV-2009-0572","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0572"},{"name":"52300","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/52300"},{"tags":["x_refsource_MISC"],"url":"http://lampsecurity.org/node/28"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/386606"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/386604"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0817","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with \"administer site configuration\" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://drupal.org/node/385950","refsource":"CONFIRM","url":"http://drupal.org/node/385950"},{"name":"34060","refsource":"SECUNIA","url":"http://secunia.com/advisories/34060"},{"name":"protectednode-passwordpage-xss(48980)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48980"},{"name":"ADV-2009-0572","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/0572"},{"name":"52300","refsource":"OSVDB","url":"http://osvdb.org/52300"},{"name":"http://lampsecurity.org/node/28","refsource":"MISC","url":"http://lampsecurity.org/node/28"},{"name":"http://drupal.org/node/386606","refsource":"CONFIRM","url":"http://drupal.org/node/386606"},{"name":"http://drupal.org/node/386604","refsource":"CONFIRM","url":"http://drupal.org/node/386604"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0817","datePublished":"2009-03-05T02:00:00.000Z","dateReserved":"2009-03-04T00:00:00.000Z","dateUpdated":"2024-08-07T04:48:52.319Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-03-05 02:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:5.x:*:*:*:*:*:*:*","matchCriteriaId":"CA409222-79A5-4C9D-8D79-5F634A61E0FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:5.x-1.0:*:*:*:*:*:*:*","matchCriteriaId":"63D34BF7-DDAE-4F29-93CD-503679FAAF24"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:5.x-1.2:*:*:*:*:*:*:*","matchCriteriaId":"BEEE7794-247D-4303-A426-C68CD0F934AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:5.x-1.3:*:*:*:*:*:*:*","matchCriteriaId":"8F817243-DF82-4B24-992C-6FA4CC0038C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:5.x-1.x-dev:*:*:*:*:*:*:*","matchCriteriaId":"A507F00C-8570-4265-86F4-CE13CD59F79D"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:6.x-1.0:*:*:*:*:*:*:*","matchCriteriaId":"CF91738E-F092-4339-95C1-BA5696C3B935"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:6.x-1.2:*:*:*:*:*:*:*","matchCriteriaId":"6AE752A2-612D-4E1D-9A6B-3D36CC009245"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:6.x-1.3:*:*:*:*:*:*:*","matchCriteriaId":"171053F8-66E2-4DA1-A54B-3C6D96488E50"},{"vulnerable":true,"criteria":"cpe:2.3:a:drupal:protected_node_module:6.x-1.4:*:*:*:*:*:*:*","matchCriteriaId":"9C785797-2B53-4799-9B52-07FCC418ADD4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","matchCriteriaId":"799CA80B-F3FA-4183-A791-2071A7DA1E54"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"817","Ordinal":"1","Title":"CVE-2009-0817","CVE":"CVE-2009-0817","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"817","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with \"administer site configuration\" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.","Type":"Description","Title":"CVE-2009-0817"},{"CveYear":"2009","CveId":"817","Ordinal":"2","NoteData":"2009-03-04","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"817","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}