Security Advisory

CVE-2008-6533

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-03-26 20:28:00
Last updated 2024-08-07 11:34:47
Assigner mitre
State PUBLISHED

Description

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.