First published: Mon Nov 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Viewvc Viewvc | >=1.0.0<1.0.13 | |
Viewvc Viewvc | >=1.1.0<1.1.16 | |
Debian Debian Linux | =6.0 | |
Debian Debian Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.