First published: Wed Dec 20 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, which do not use the check_plain function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal Project | =4.7 | |
Drupal Drupal Project | =4.7_1.0 | |
Drupal Drupal Project Issue Tracking | =4.7_2.0 | |
Drupal Drupal Project Issue Tracking | =4.7_1.0 | |
Drupal Drupal Project | =4.6 | |
Drupal Drupal Project | =4.7_2.0 | |
Drupal Drupal Project | =4.6_1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.