Looks to me like it is dependent on which version of PHP is being used. Older versions running Drupal might still be vulnerable. Using PHP 4.3.10, I was not able to duplicate any of the example XSS attacks.<br>