Unrated severityNVD Advisory· Published May 1, 2009· Updated Apr 23, 2026
CVE-2009-1501
CVE-2009-1501
Description
Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- drupal.org/node/448958nvdPatchVendor Advisory
- www.securityfocus.com/bid/34774nvdPatch
- secunia.com/advisories/34953nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1213nvd
News mentions
0No linked articles in our index yet.