CVE-2008-3741
27.08.2008, 15:21
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.
Vendor | Product | Version |
---|---|---|
drupal | drupal | 5.0 |
drupal | drupal | 5.1 |
drupal | drupal | 5.2 |
drupal | drupal | 5.3 |
drupal | drupal | 5.4 |
drupal | drupal | 5.5 |
drupal | drupal | 5.6 |
drupal | drupal | 5.7 |
drupal | drupal | 5.8 |
drupal | drupal | 5.9 |
drupal | drupal | 6.0 |
drupal | drupal | 6.1 |
drupal | drupal | 6.2 |
drupal | drupal | 6.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References