Description
|
|
Multiple vulnerabilities were identified in Drupal, which could be exploited by malicious users to bypass security restrictions or conduct cross site scripting attacks.
The first flaw is due to input validation errors when processing specially crafted variables, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.
The second vulnerability is due to an error where HTML attachments are opened insecurely in the browser, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
The third issue is due to an error in the "access user profile" permission when the server is running PHP 5, which may be exploited by attackers to disclose sensitive information.
|