Vulnerable Systems:
* Drupal 4.7.x before version 4.7.8.
* Drupal 5.x before version 5.3.
In some circumstances Drupal allows user-supplied data to become part of response headers. As this user-supplied data is not always properly escaped, this can be exploited by malicious users to execute HTTP response splitting attacks which may lead to a variety of issues, among them cache poisoning, cross-user defacement and injection of arbitrary code.
Vendor Status:
Drupal issued an update for this vulnerability