Vulnerability Bulletins |
SA-CORE-2009-009 - Drupal Core - Cross site scripting |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-CORE-2009-009Project: Drupal coreVersion: 5.x, 6.xDate: 2009-December-16Security risk: Not criticalExploitable from: RemoteVulnerability: Cross site scriptingDescriptionMultiple vulnerabilities were discovered in Drupal.Contact category name cross-site scriptingThe Contact module does not correctly handle certain user input when displaying category information. Users privileged to create contact categories can insert arbitrary HTML and script code into the contact module More info: https://www.drupal.org/node/661586 |
|






