Support for Drupal 7 is ending on 5 January 2025—it’s time to migrate to Drupal 10! Learn about the many benefits of Drupal 10 and find migration tools in our resource center.
By jvandyk on
- Advisory ID: DRUPAL-SA-2006-002
- Project: Drupal core
- Date: 2006-03-13
- Security risk: less critical
- Impact: cross-site scripting
- Where: from remote
- Vulnerability: cross-site scripting
Description
Some user input sanity checking was missing. This could lead to possible cross-site scripting (XSS) attacks.
XSS can lead to user tracking and theft of accounts and services.
Versions affected
All Drupal versions before 4.6.6.
Solution
- If you are running Drupal 4.5.x then upgrade to Drupal 4.5.8.
- If you are running Drupal 4.6.x then upgrade to Drupal 4.6.6.
Contact
The security contact for Drupal can be reached at security at drupal.org or using the form at http://drupal.org/contact.
More information is available from http://drupal.org/security or from our security RSS feed http://drupal.org/security/rss.xml.