CVE-2011-5221: XSS
Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5221?
CVE-2011-5221 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2011-5221?
To fix CVE-2011-5221, upgrade to WebSVN version 2.3.1 or later.
Which versions of WebSVN are affected by CVE-2011-5221?
CVE-2011-5221 affects WebSVN versions prior to 2.3.1 along with specific versions like 1.61, 2.0, 2.1.0, 2.2.0, and 2.2.1.
What are the potential consequences of exploiting CVE-2011-5221?
Exploiting CVE-2011-5221 may allow attackers to inject malicious web scripts or HTML, compromising user data or session integrity.
Is user input related to the path parameter in WebSVN susceptible in CVE-2011-5221?
Yes, user input passed through the path parameter in specific WebSVN scripts is vulnerable to XSS in CVE-2011-5221.