Cross-Site Scripting Vulnerability in Module Category Tokens 6.x
Category tokens is a Drupal® module that displays additional tokens, relating to the first and last terms in a category.
Affected Application: Category tokens 6.x.
Issue: On 07/08/11, a cross-site scripting vulnerability was reported for Drupal module Category tokens 6.x. The vulnerability lets attackers with the "administer taxonomy" permission use cross-site scripting to gain administrative access.
Resolution: Update to the most recent version of the Category tokens module. For more information, see the Category tokens page on Drupal's site:
http://drupal.org/project/category_tokens
We compiled this information using the National Vulnerability Database. For more information about this issue, see the summary for CVE-2010-4813. To learn more about cross-site scripting vulnerabilities, see Cross-Site Scripting.
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.