---
title: "CVE-2006-0070\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-0070?format=md
keywords: index, follow
---

# CVE-2006-0070

Publication date 4 January 2006

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Drupal allows remote attackers to conduct cross-site scripting (XSS)
attacks via an IMG tag with an unusual encoded Javascript function name, as
demonstrated using variations of the alert() function. NOTE: a followup by
the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when
"Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by
design, perhaps this should not be included in CVE

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Fixed 2.0.0.6+1-0ubuntu1 |
| 6.10 edgy | Fixed 2.0.0.6+0dfsg-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0070)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-0070)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-0070)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-0070)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-0070>
