Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
Link | Tags |
---|---|
http://secunia.com/advisories/14515 | third party advisory patch vendor advisory |
http://drupal.org/files/drupal-4.5-xss-fix.patch | patch |
http://drupal.org/drupal-4.5.2 | patch vendor advisory |