Vulnerable Systems:
* Drupal versions before 4.6.6.
Some user input sanity checking was missing. This could lead to possible cross-site scripting (XSS) attacks. XSS can lead to user tracking and theft of accounts and services.
Vendor Status:
Drupal as issued an update for this vulnerablity.