|
|
| |
|
| |
websvn: multiple vulnerabilities
| Package(s): | websvn |
CVE #(s): | CVE-2008-5918
CVE-2008-5919
|
| Created: | March 9, 2009 |
Updated: | March 11, 2009 |
| Description: |
From the Gentoo advisory:
James Bercegay of GulfTech Security reported a Cross-site scripting
(XSS) vulnerability in the getParameterisedSelfUrl() function in
index.php (CVE-2008-5918) and a directory traversal vulnerability in
rss.php when magic_quotes_gpc is disabled (CVE-2008-5919).
A remote attacker can exploit these vulnerabilities to overwrite
arbitrary files, to read changelogs or diffs for restricted projects
and to hijack a user's session.
|
| Alerts: |
|
( Log in to post comments)
|
|
|