See: http://drupal.org/node/280571
rerating, all of these issues are B3 or B4.
fixing whiteboard, since all versions are in ~arch web-apps, please bump
new versions are in the tree. No stable version existed, so seems that we are done here...
thanks, closing without GLSA.
*** Bug 232058 has been marked as a duplicate of this bug. ***
CVE-2008-3218 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3218): Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values. CVE-2008-3219 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3219): The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism. CVE-2008-3220 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3220): Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." CVE-2008-3221 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3221): Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities. CVE-2008-3222 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3222): Session fixation vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. CVE-2008-3223 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3223): SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."