>> Drupal Internationalization and Localizer Multiple Vulnerabilities
Title : Drupal Internationalization and Localizer Multiple Vulnerabilities VUPEN ID : VUPEN/ADV-2008-1352 CVE ID : CVE-2008-1976 - CVE-2008-1977
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-25
Technical Description
Two vulnerabilities have been identified in Internationalization and Localizer (modules for Drupal), which could be exploited by attackers to execute arbitrary scripting code or manipulate certain data. These issues are caused by input validation errors when displayed user-supplied values and HTTP requests, which could be exploited by attackers to cause arbitrary scripting code to be executed by a user's browser in the security context of an affected Web site or conduct cross site request forgery attacks.