A bug in the output filter employed by Drupal makes it possible for malicious users to insert script code into pages (cross site scripting or XSS).
A bug in the private filesystem trusts the MIME type sent by the browser, enabling malicious users with the ability to upload files to execute cross site scripting attacks.
These bugs affects both Drupal 5.x and 6.x.
Vendor Status:
Drupal issued an update for this vulnerability