Description
Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.
Remediation
References
Related Vulnerabilities
WordPress Plugin RocketTheme RokBox 'jwplayer.swf' Cross-Site Scripting (2.11)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5497)
WordPress 4.4.x Cross-Domain Flash Injection Vulnerability (4.4 - 4.4.13)
Oracle Application Server Other Vulnerability (CVE-2004-2134)