Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-0273
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0273

Description:
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/39619

SAID
  Secunia Advisory: SA28486
  Secunia Advisory: SA28422

CONFIRM
  http://www.vbdrupal.org/forum/showthread.php?t=1349
  http://www.vbdrupal.org/forum/showthread.php?p=6878
  http://drupal.org/node/208564

BID
  27238


Return to the previous page.