Drupal FileField version 6.x-3.3 suffers from an arbitrary script injection vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/90765/drupalfilefield-inject.txt
Source: https://packetstormsecurity.com/files/90765/Drupal-FileField-6.x-3.3-Arbitrary-Script-Injection.html