Users with “administer actions permission” can enter action descriptions and messages which are not properly filtered on output. Users with content and taxonomy tag submission permissions can create nodes and taxonomy terms which are not properly sanitized for inclusion in action messages and inject arbitrary HTML and script code into Drupal pages. Such a cross-site scripting attack may lead to the malicious user gaining administrative access.
https://drupal.org/node/880476
This vulnerability affects the following application versions:
- Drupal 6.0
- Drupal 6.1
- Drupal 6.2
- Drupal 6.3
- Drupal 6.4
- Drupal 6.5
- Drupal 6.6
- Drupal 6.7
- Drupal 6.8
- Drupal 6.9
- Drupal 6.10
- Drupal 6.11
- Drupal 6.12
- Drupal 6.13
- Drupal 6.14
- Drupal 6.15
- Drupal 6.16
- Drupal 6.17