Description
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Remediation
References
Related Vulnerabilities
PrestaShop Improper Privilege Management Vulnerability (CVE-2013-6295)
WordPress Plugin Contact Form 7 Redirect & Thank You Page Cross-Site Request Forgery (1.0.3)
MySQL CVE-2018-3081 Vulnerability (CVE-2018-3081)
Oracle Application Server Other Vulnerability (CVE-2001-1372)
WordPress Plugin Sendit WP Newsletter 'submit.php' Blind SQL Injection (1.5.9)