Drupal · Drupal · CVE-2006-5475
**Name of the Vulnerable Software and Affected Versions**
Drupal versions 4.6.x before 4.6.10
Drupal versions 4.7.x before 4.7.4
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed, due to multiple cross-site scripting (XSS) vulnerabilities in the XML parser.
**Recommendations**
For Drupal versions 4.6.x before 4.6.10, update to version 4.6.10 or later.
For Drupal versions 4.7.x before 4.7.4, update to version 4.7.4 or later.