Drupal Other Vulnerability - CVE-2006-2832 - Vulnerability Database

Drupal Other Vulnerability - CVE-2006-2832

Low
Reference: CVE-2006-2832
Title: Drupal Other Vulnerability
Overview:

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.