Needs review
Project:
Drupal Long Term Support (LTS)
Version:
5.x-1.x-dev
Component:
Core
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
16 Jun 2011 at 21:22 UTC
Updated:
16 Jun 2011 at 21:59 UTC
See: http://drupal.org/node/1168756
"A reflected cross site scripting vulnerability was discovered in Drupal's error handler. Drupal displays PHP errors in the messages area, and a specially crafted URL can cause malicious scripts to be injected into the message. The issue can be mitigated by disabling on-screen error display at admin/settings/error-reporting. This is the recommended setting for production sites.
This issue affects Drupal 6.x only."
Comments
Comment #1
johnbarclay commentedDrupal 6 patches:
http://drupalcode.org/project/drupal.git/blobdiff/8636b1234c84a07f0f087c...
This seems to map directly for 6 to 5?