CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2009-1575

MEDIUM
4.3
CVSS Severity Score
EPSS Score0.1590%
EPSS Percentile32.41th
Published2009年5月6日
Last Modified2026年4月23日

Vulnerability Description

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

Affected Platforms (CPE)

📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.0
📦
Drupal

Drupal

= 5.1
📦
Drupal

Drupal

= 5.1_rev1.1
📦
Drupal

Drupal

= 5.2
📦
Drupal

Drupal

= 5.3
📦
Drupal

Drupal

= 5.4
📦
Drupal

Drupal

= 5.5
📦
Drupal

Drupal

= 5.5.
📦
Drupal

Drupal

= 5.6
📦
Drupal

Drupal

= 5.7
📦
Drupal

Drupal

= 5.8
📦
Drupal

Drupal

= 5.9
📦
Drupal

Drupal

= 5.10
📦
Drupal

Drupal

= 5.11
📦
Drupal

Drupal

= 5.12
📦
Drupal

Drupal

= 5.13
📦
Drupal

Drupal

= 5.14
📦
Drupal

Drupal

= 5.15
📦
Drupal

Drupal

= 5.16
📦
Drupal

Drupal

= 6
📦
Drupal

Drupal

= 6
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.0
📦
Drupal

Drupal

= 6.1
📦
Drupal

Drupal

= 6.2
📦
Drupal

Drupal

= 6.3
📦
Drupal

Drupal

= 6.4
📦
Drupal

Drupal

= 6.5
📦
Drupal

Drupal

= 6.6
📦
Drupal

Drupal

= 6.7
📦
Drupal

Drupal

= 6.8
📦
Drupal

Drupal

= 6.9
📦
Drupal

Drupal

= 6.10

References & Advisories

相關漏洞威脅