CVE-2006-5442: XSS
Published Oct 21, 2006
·Updated
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view.
Affected Software
1 affected component
viewvc ViewVC<=1.0.2
Event History
Oct 21, 2006
CVE Published
12:07 AM
Data Sourced
via NVD·12:07 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5442?
CVE-2006-5442 has a moderate severity rating due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2006-5442?
To fix CVE-2006-5442, upgrade to ViewVC version 1.0.3 or later.
3
What types of attacks can CVE-2006-5442 facilitate?
CVE-2006-5442 can facilitate cross-site scripting (XSS) attacks that allow injection of arbitrary JavaScript code.
4
Which versions of ViewVC are affected by CVE-2006-5442?
CVE-2006-5442 affects ViewVC versions 1.0.2 and earlier.
5
Can CVE-2006-5442 be exploited without authentication?
Yes, CVE-2006-5442 can be exploited by remote attackers without requiring authentication.