Vulnerability Bulletins |
SA-2008-047 - Drupal core - Multiple vulnerabilities |
|
| Affected software | Drupal |
|
Advisory ID: DRUPAL-SA-2008-047Project: Drupal coreVersion: 5.x, 6.xDate: 2008-August-13Security risk: Highly criticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabilities and weaknesses were discovered in Drupal.Cross site scriptingA bug in the output filter employed by Drupal makes it possible for malicious users to insert script code into pages (cross site scripting or XSS). A bug in the private filesystem trusts the MIME type sent by the browser, More info: https://www.drupal.org/node/295053 |
|






