LWN.net Logo

gnatsweb: cross-site scripting

Package(s):gnatsweb CVE #(s):CVE-2007-2808
Created:February 6, 2008 Updated:February 6, 2008
Description: From the Debian advisory: "r0t" discovered that gnatsweb, a web interface to GNU GNATS, did not correctly sanitize the database parameter in the main CGI script. This could allow the injection of arbitrary HTML, or javascript code.
Alerts:
Debian DSA-1486-1 2008-02-04

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.