CVE-2008-1133
Publication date 4 March 2008
Last updated 24 July 2024
Ubuntu priority
Description
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.