Drupal · Drupal · CVE-2008-0274
**Name of the Vulnerable Software and Affected Versions**
Drupal versions 4.7.x through 5.x
**Description**
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files, when certain .htaccess protections are disabled.
**Recommendations**
For versions 4.7.x through 5.x, enable .htaccess protections to prevent exploitation.
As a temporary workaround, consider restricting access to theme .tpl.php files until a fix is applied.