Vulnerability Bulletins

SA-CORE-2009-007 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2009-007Project: Drupal coreVersion: 5.x, 6.xDate: 2009-July-1Security risk: Moderately criticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities and weaknesses were discovered in Drupal.Cross-site scriptingThe Forum module does not correctly handle certain arguments obtained from the URL. By enticing a suitably privileged user to visit a specially crafted URL, a malicious user is able to insert arbitrary HTML and

More info:

https://www.drupal.org/node/507572