Titles are not escaped prior to being displayed on content edit forms, allowing users to inject arbitrary HTML and script code into these pages.
http://www.cvedetails.com/cve/CVE-2008-1133/
https://drupal.org/node/227608
This vulnerability affects the following application versions:
- Drupal 6.0