Vulnerable Systems:
* Drupal 4.6.x versions before Drupal 4.6.8.
* Drupal 4.7.x versions before Drupal 4.7.2.
It is possible for a malicious user to insert and execute XSS into terms, due to lack of validation on output of the page title. The fix wraps the display of terms in check_plain().
Vendor Status:
Drupal issued an update for this vulnerability