Description
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
References (3)
Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://drupal.org/node/227608
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/29118
Patch, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/28026
Scores
EPSS
0.0046
EPSS Percentile
64.5%
Details
CWE
CWE-79
Status
published
Products (1)
drupal/drupal
6.0
Published
Mar 04, 2008
Tracked Since
Feb 18, 2026