The Drupal team reports:
---Vulnerability: SQL injection vulnerability.
-A security vulnerability in the database layer allowed - certain queries to be submitted to the database without - going through Drupal's query sanitizer.
-
-Vulnerability: Execution of arbitrary files in certain - Apache configurations
-Certain -- alas, typical -- configurations of Apache allows - execution of carefully named arbitrary scripts in the files - directory. Drupal now will attempt to automatically create - a .htaccess file in your "files" directory to protect you.
-
Vulnerability: XSS Vulnerability in taxonomy module
It is possible for a malicious user to insert and execute @@ -69,10 +55,13 @@ Note: Please add new entries to the beginning of this file.