Vulnerability Bulletins

SA-CORE-2009-009 - Drupal Core - Cross site scripting

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2009-009Project: Drupal coreVersion: 5.x, 6.xDate: 2009-December-16Security risk: Not criticalExploitable from: RemoteVulnerability: Cross site scriptingDescriptionMultiple vulnerabilities were discovered in Drupal.Contact category name cross-site scriptingThe Contact module does not correctly handle certain user input when displaying category information. Users privileged to create contact categories can insert arbitrary HTML and script code into the contact module

More info:

https://www.drupal.org/node/661586