Vulnerability Bulletins

SA-2008-044 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-2008-044Project: Drupal coreVersion: 5x, 6.xDate: 2008-July-9Security risk: Moderately criticalExploitable from: RemoteVulnerability: Multiple vulnerabilitiesDescriptionMultiple vulnerabities and weaknesses were discovered in Drupal. Neither of these are readily exploitable.Cross site scriptingFree tagging taxonomy terms can be used to insert arbitrary script and HTML code (cross site scripting or XSS) on node preview pages. A successful exploit requires that the victim

More info:

https://www.drupal.org/node/280571