Some values from OpenID providers are output without being properly escaped, allowing malicious providers to insert arbitrary script and HTML code (XSS) into user pages. This issue affects Drupal 6.x only.

filter_xss_admin() has been hardened to prevent use of the object HTML tag in administrator input.

http://www.cvedetails.com/cve/CVE-2008-3218/

https://drupal.org/node/280571

This vulnerability affects the following application versions:

  • Drupal 6.0
  • Drupal 6.1
  • Drupal 6.2

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *