CVE-2016-1236: XSS
A vulnerability was found in websvn. Having a directory or file in a repository with its filename containing a XSS payload will cause it to be executed in various parts of the application.
References:
http://seclists.org/oss-sec/2016/q2/257
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1236?
CVE-2016-1236 is considered a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2016-1236?
To fix CVE-2016-1236, ensure that you update to the latest version of WebSVN or apply patches that address the XSS vulnerability.
What vulnerabilities does CVE-2016-1236 exploit?
CVE-2016-1236 exploits cross-site scripting by executing malicious payloads from file or directory names in a repository.
Which software is affected by CVE-2016-1236?
CVE-2016-1236 affects WebSVN and Debian 8.0 systems that utilize the application.
Is CVE-2016-1236 still a threat?
While fixes exist, CVE-2016-1236 can still pose a threat if systems remain unpatched or misconfigured.