CVE-2009-3121
Description
Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting (XSS) in Drupal Ajax Table module 5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Vulnerability
The Ajax Table module for Drupal 5.x lacks proper escaping of certain user-supplied values [1]. This allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary HTML and script content into pages [1]. The exact vectors are unspecified in the advisory, but the module is used to create AJAX-refreshable tables via parameters [1].
Exploitation
An attacker can exploit this vulnerability by providing malicious input to the module's parameters [1]. No authentication is required as the module is accessible remotely [1]. The advisory notes that the module also suffers from access bypass, but the XSS specifically requires only the ability to submit crafted input [1].
Impact
Successful exploitation allows the attacker to inject arbitrary web script or HTML, which can lead to session hijacking, defacement, or even gaining administrative access if the admin views the malicious page [1].
Mitigation
As of the advisory date (2009-Aug-26), there is no solution available [1]. The recommended action is to disable the Ajax Table module and remove it from the server [1]. Drupal core is not affected [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:a:chris_shattuck:ajaxtable:5.x-1.x-dev:*:*:*:*:*:*:*
- Range: 5.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- drupal.org/node/560298nvdPatchVendor Advisory
- secunia.com/advisories/36497nvdVendor Advisory
- www.vupen.com/english/advisories/2009/2452nvdVendor Advisory
- osvdb.org/57436nvd
- www.securityfocus.com/bid/36165nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/52819nvd
News mentions
0No linked articles in our index yet.