CVE-2008-1133 Information

Description

The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript which allows remote attackers to conduct cross-site scripting (XSS) attacks.

Reference

http://drupal.org/node/227608 http://secunia.com/advisories/29118 http://www.securityfocus.com/bid/28026

Share on: