|
|
| |
|
| |
info2www: missing input sanitizing
| Package(s): | info2www |
CVE #(s): | CAN-2004-1341
|
| Created: | April 19, 2005 |
Updated: | April 20, 2005 |
| Description: |
Nicolas Gregoire discovered a cross-site scripting vulnerability in
info2www, a converter for info files to HTML. A malicious person could
place a harmless looking link on the web that could cause arbitrary
commands to be executed in a user's browser. |
| Alerts: |
|
( Log in to post comments)
|
|
|