Description
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin BackWPup Multiple Unspecified Vulnerabilities (3.2.1)
CubeCart Improper Input Validation Vulnerability (CVE-2013-1465)
Zope Web Application Server Other Vulnerability (CVE-2002-0688)
WordPress Plugin Canalplan Cross-Site Scripting (3.22)
Django Insufficiently Protected Credentials Vulnerability (CVE-2018-16984)