Secunia Security Advisory – Some vulnerabilities have been reported in the User Karma module for Drupal, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site scripting attacks.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/72353/sa32904.txt
Source: https://packetstormsecurity.com/files/72353/Secunia-Security-Advisory-32904.html