>> Drupal "Filter" and "System" Modules Multiple Arguments Cross Site Scripting Issues
Title : Drupal "Filter" and "System" Modules Multiple Arguments Cross Site Scripting Issues VUPEN ID : VUPEN/ADV-2007-0050 CVE ID : CVE-2007-0136
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-05
Technical Description
Multiple vulnerabilities have been identified in Drupal, which may be exploited by attackers to execute arbitrary scripting code. These issues are due to input validation errors in the "filter" and "system" modules when processing certain arguments, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.