Vulnerability Bulletins

SA-2008-018 - Drupal core - Cross site scripting

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-2008-018Project: Drupal coreVersion: 6.0Date: 2008-February-27Security risk: Moderately criticalExploitable from: RemoteVulnerability: Multiple cross site scripting vulnerabilitiesDescriptionTitles are not escaped prior to being displayed on content edit forms, allowing users to inject arbitrary HTML and script code into these pages.The Drupal.checkPlain function, used to escape text in ECMAScript, contains a bug which causes it to escape only the first instance of a

More info:

https://www.drupal.org/node/227608