Drupal · Drupal · CVE-2006-2260
**Name of the Vulnerable Software and Affected Versions**
Drupal versions 4.5 through 4.6
**Description**
A cross-site scripting (XSS) issue exists in the project module, allowing remote attackers to inject arbitrary web script or HTML. The exact attack vectors are not specified.
**Recommendations**
For versions 4.5 and 4.6, update to a newer version to mitigate the risk, as these versions are affected by the XSS vulnerability in the project module.