Security Advisory

CVE-2008-3741

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-08-27 15:00:00
Last updated 2024-08-07 09:52:59
Assigner mitre
State PUBLISHED

Description

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.