* Advisory ID: DRUPAL-SA-CONTRIB-2009-021
* Project: CCK comment reference (third-party module)
* Version: 6.x
* Date: 2009 April 15
* Security risk: Moderately critical
* Exploitable from: Remote
* Vulnerability: Cross-site scripting (XSS)
-------- DESCRIPTION ---------------------------------------------------------
CCK comment reference project, lets administrators define node fields that
are references to comments. When displaying a node edit form, the titles of
candidate referenced comments are not properly filtered, allowing malicious