Locale module and dependent contributed modules do not sanitize the display of language codes, native and English language names properly. While these usually come from a preselected list, arbitrary administrator input is allowed. This vulnerability is mitigated by the fact that the attacker must have a role with the 'administer languages' permission.
This issue affects Drupal 5.x and 6.x.
Vendor Status:
Drupal issued an update for this vulnerability