Description
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery PhotoBlocks Cross-Site Scripting (1.1.42)
Oracle Database Server CVE-2009-1995 Vulnerability (CVE-2009-1995)
MySQL CVE-2021-35622 Vulnerability (CVE-2021-35622)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2335)
WordPress Plugin Tune Library 'letter' Parameter SQL Injection (1.5.1)