CVE-2008-3219 Information
Description
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not \prevent use of the object HTML tag in administrator input\ which has unknown impact and attack vectors probably related to an insufficient cross-site scripting (XSS) protection mechanism.
Reference
http://drupal.org/node/280571 http://secunia.com/advisories/31079 http://www.openwall.com/lists/oss-security/2008/07/10/3 http://www.securityfocus.com/bid/30168 https://bugzilla.redhat.com/show_bug.cgi?id=454849 https://exchange.xforce.ibmcloud.com/vulnerabilities/43701 https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00016.html https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00527.html https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00551.html
Share on: