drupal
Page content
- Author: Miklos Vajna
- Vulnerable: 5.16-1
- Unaffected: 5.17-1anacreon1
Some vulnerabilities have been reported in Drupal, which can be exploited by malicious people to conduct script insertion attacks or to disclose potentially sensitive information.
- User provided input is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user’s browser session in context of an affected site when the malicious data is viewed and interpreted as UTF-7. Successful exploitation requires the ability to post content.
- An unspecified error can be exploited to disclose information about form submissions when a user is tricked into submitting a form after following a specially crafted link to the site. This can further be exploited to conduct e.g. cross-site request forgery attacks.
- Bug Tracker URL: http://bugs.frugalware.org/task/3759
CVEs:
- No CVE, see http://drupal.org/node/449078.