CVE-2008-0274

N/A Unknown
Published: January 15, 2008 Modified: April 23, 2026
View on NVD

Description

Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://drupal.org/node/208565
Source: cve@mitre.org
http://secunia.com/advisories/28422
Source: cve@mitre.org
Patch
http://www.securityfocus.com/bid/27238
Source: cve@mitre.org
Patch
http://drupal.org/node/208565
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28422
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://secunia.com/advisories/28486
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/27238
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.vbdrupal.org/forum/showthread.php?p=6878
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vbdrupal.org/forum/showthread.php?t=1349
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0127
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0134
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/39605
Source: af854a3a-2127-422b-91ae-364da2661108

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.5%
72th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

drupal