Description
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Remediation
References
Related Vulnerabilities
Joomla! Core Denial of Service (2.5.0 - 3.9.27)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2017-2608)
WordPress Plugin Connector for Gravity Forms and Google Sheets Cross-Site Scripting (1.1.0)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31545)