• Advisory ID: DRUPAL-SA-CONTRIB-2010-024
  • Project: eTracker (third-party module)
  • Version: 6.x-1.1
  • Date: 2010-March-03
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting


The eTracker module provides integration of a Drupal site with the eTracker web traffic analysis service and takes the current URL as a parameter to track what pages have been visited. The URL from the browser is forwarded to JavaScript in the current page, and because the URL wasn't sanitised, it could have allowed cross-site scripting attacks by appending malicious code to the URL.

Versions affected

  • eTracker prior to 6.x-1.2.

Drupal core is not affected. If you do not use the contributed eTracker module, there is nothing you need to do.


Install the latest version:

See also the eTracker project page.

Reported by

  • Andreas Harder

Fixed by

  • Jürgen Haas (jurgenhaas), the module maintainer.


The security contact for Drupal can be reached at security at drupal.org or via the form at http://drupal.org/contact.