Titles are not escaped prior to being displayed on content edit forms, allowing users to inject arbitrary HTML and script code into these pages.

http://www.cvedetails.com/cve/CVE-2008-1133/

https://drupal.org/node/227608

This vulnerability affects the following application versions:

  • Drupal 6.0

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *