Vulnerability Bulletins

SA-CORE-2010-001 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2010-001Project: Drupal coreVersion: 5.x, 6.xDate: 2010-March-03Security risk: CriticalExploitable from: RemoteVulnerability: Cross site scripting, Open redirect, Authorization vulnerabilityDescriptionMultiple vulnerabilities and weaknesses were discovered in Drupal.Installation cross site scriptingA user-supplied value is directly output during installation allowing a malicious user to craft a URL and perform a cross-site scripting attack. The exploit can only be

More info:

https://www.drupal.org/node/731710