aboutsummaryrefslogtreecommitdiffstats
path: root/security/vuxml/vuln.xml
diff options
context:
space:
mode:
Diffstat (limited to 'security/vuxml/vuln.xml')
-rw-r--r--security/vuxml/vuln.xml20
1 files changed, 10 insertions, 10 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index 6c90ce42c46..0ac61665b25 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -42,7 +42,7 @@ Note: Please add new entries to the beginning of this file.
<range><lt>5.12</lt></range>
</package>
<package>
- <name>drupal6</name>
+ <name>drupal6</name>
<range><lt>6.6</lt></range>
</package>
</affects>
@@ -51,15 +51,15 @@ Note: Please add new entries to the beginning of this file.
<p>The Drupal Project reports:</p>
<blockquote cite="http://drupal.org/node/324824">
<p>On a server configured for IP-based virtual hosts, Drupal may be
- caused to include and execute specifically named files outside
- of its root directory. This bug affects both Drupal 5 and
- Drupal 6.</p>
- <p>The title of book pages is not always properly escaped, enabling
- users with the "create book content" permission or the
- permission to edit any node in the book hierarchy to insert
- arbitrary HTML and script code into pages. Such a Cross site
- scripting attack may lead to the attacker gaining administrator
- access. This bug affects Drupal 6.</p>
+ caused to include and execute specifically named files outside
+ of its root directory. This bug affects both Drupal 5 and
+ Drupal 6.</p>
+ <p>The title of book pages is not always properly escaped, enabling
+ users with the "create book content" permission or the
+ permission to edit any node in the book hierarchy to insert
+ arbitrary HTML and script code into pages. Such a Cross site
+ scripting attack may lead to the attacker gaining administrator
+ access. This bug affects Drupal 6.</p>
</blockquote>
</body>
</description>