- Advisory ID: DRUPAL-SA-CONTRIB-2010-052
- Projects: Multiple third party modules - Privatemsg, Weather Underground, Tellafriend, Menu Block Split, osCommerce, Download Count, Comment Page, False Account Detector, User Queue
- Version: 5.x, 6.x
- Date: 2010-05-19
- Security risks: Critical
- Exploitable from: Remote
- Vulnerability: Multiple (Cross-site Request Forgery, Cross-site scripting, Email header injection, SQL Injection)









