Security Advisory
CVE-2010-1998
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers.