Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/119598/Drupal-Core-6.x-7.x-Cross-Site-Scripting-Access-Bypass.html | |
http://seclists.org/oss-sec/2013/q1/211 | mailing list |
http://osvdb.org/89306 | vdb entry |
http://www.debian.org/security/2013/dsa-2776 | vendor advisory |
http://seclists.org/fulldisclosure/2013/Jan/120 | mailing list |
https://drupal.org/SA-CORE-2013-001 | patch vendor advisory |