Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://drupal.org/node/507572 | patch vendor advisory |
http://secunia.com/advisories/35681 | third party advisory |
http://www.securitytracker.com/id?1022497 | vdb entry third party advisory patch |
http://osvdb.org/55525 | vdb entry broken link |