{"api_version":"1","generated_at":"2026-07-24T20:47:25+00:00","cve":"CVE-2009-2083","urls":{"html":"https://cve.report/CVE-2009-2083","api":"https://cve.report/api/cve/CVE-2009-2083.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2083","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2083"},"summary":{"title":"CVE-2009-2083","description":"Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via \"Parent and related terms.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-06-16 21:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://drupal.org/node/487620","name":"http://drupal.org/node/487620","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"taxonomy_manager 5.x-1.2 | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35286","name":"http://www.securityfocus.com/bid/35286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Taxonomy Manager Administrative Page HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lampsecurity.org/drupal-6-taxonomy-manager-xss-vulnerability","name":"http://lampsecurity.org/drupal-6-taxonomy-manager-xss-vulnerability","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","URL Repurposed"],"title":"Drupal 6 Taxonomy Manager XSS Vulnerability | Linux/Apache/MySQL/PHP Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://drupal.org/node/487818","name":"http://drupal.org/node/487818","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SA-CONTRIB-2009-034 -  Taxonomy manager - Cross site scripting | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35391","name":"http://secunia.com/advisories/35391","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Drupal Taxonomy Manager Module Script Insertion Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2083","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2083","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2083","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2083","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mattias_hutterer","cpe5":"taxonomy_manager","cpe6":"5.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2083","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mattias_hutterer","cpe5":"taxonomy_manager","cpe6":"5.x-1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2083","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mattias_hutterer","cpe5":"taxonomy_manager","cpe6":"5.x-1.x-dev","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:36:20.978Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lampsecurity.org/drupal-6-taxonomy-manager-xss-vulnerability"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/487620"},{"name":"35391","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35391"},{"name":"35286","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35286"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/487818"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via \"Parent and related terms.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-06-16T20:26:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://lampsecurity.org/drupal-6-taxonomy-manager-xss-vulnerability"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/487620"},{"name":"35391","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35391"},{"name":"35286","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35286"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/487818"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2083","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via \"Parent and related terms.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://lampsecurity.org/drupal-6-taxonomy-manager-xss-vulnerability","refsource":"MISC","url":"http://lampsecurity.org/drupal-6-taxonomy-manager-xss-vulnerability"},{"name":"http://drupal.org/node/487620","refsource":"CONFIRM","url":"http://drupal.org/node/487620"},{"name":"35391","refsource":"SECUNIA","url":"http://secunia.com/advisories/35391"},{"name":"35286","refsource":"BID","url":"http://www.securityfocus.com/bid/35286"},{"name":"http://drupal.org/node/487818","refsource":"CONFIRM","url":"http://drupal.org/node/487818"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2083","datePublished":"2009-06-16T20:26:00.000Z","dateReserved":"2009-06-16T00:00:00.000Z","dateUpdated":"2024-09-16T19:56:30.424Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-06-16 21:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","matchCriteriaId":"799CA80B-F3FA-4183-A791-2071A7DA1E54"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mattias_hutterer:taxonomy_manager:5.x-1.0:*:*:*:*:*:*:*","matchCriteriaId":"68E26226-B9E5-48F0-9A8E-E0C24E6F0906"},{"vulnerable":true,"criteria":"cpe:2.3:a:mattias_hutterer:taxonomy_manager:5.x-1.1:*:*:*:*:*:*:*","matchCriteriaId":"4CD2BF2A-AC98-4F58-87D3-4F8CB7D8A7E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:mattias_hutterer:taxonomy_manager:5.x-1.x-dev:*:*:*:*:*:*:*","matchCriteriaId":"A9C94DBE-CF9C-4D97-9422-EE85A50A19B4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2083","Ordinal":"1","Title":"CVE-2009-2083","CVE":"CVE-2009-2083","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2083","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via \"Parent and related terms.\"","Type":"Description","Title":"CVE-2009-2083"},{"CveYear":"2009","CveId":"2083","Ordinal":"2","NoteData":"2009-06-16","Type":"Other","Title":"Published"}]}}}