LWN.net Logo

drupal: cross-site scripting, privilege escalation

Package(s):drupal CVE #(s):
Created:October 20, 2006 Updated:October 25, 2006
Description: Multiple cross site scripting vulnerabilities have been discovered in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4. Also an HTML attribute injection vulnerability may lead to privilege escalation in Drupal before 4.6.10 and 4.7.4.
Alerts:
OpenPKG OpenPKG-SA-2006.025 2006-10-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds