Security Update for Drupal
The developers of the Drupal content management system have released version 5.17 and 6.11 to close a cross site scripting vulnerability. The vulnerability can only be exploited if a browser interprets valid UTF8 byte sequences as UTF7. When this occurs they can become potentially dangerous. According to the report, this can include Internet Explorer 6 and in certain cases 7.
The new version also fixed a bug which allowed abuse through Cross-Site Request forgery. There are update patches available for the problems and the developers have published several advisories on vulnerabilities in extension modules from third parties.
See also:
- Drupal core - Cross site scripting
- Fivestar 0 Cross-site request forgery
- Node Access User Reference - Access bypass
- News Page - SQL Injection
- Exif - Cross site scripting
(djwm)