Cross-site Scripting in Drupal Aggregation Module by Acquia
CVE-2008-2998

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
3 July 2008

Summary

The Aggregation module in Drupal prior to version 5.x-4.4 has multiple vulnerabilities allowing remote attackers to execute unauthorized script or HTML injections through various unspecified methods. This weakness poses a significant risk to site integrity, enabling attackers to manipulate user sessions and present malicious content to unsuspecting users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.