LWN.net Logo

websvn: multiple vulnerabilities

Package(s):websvn CVE #(s):CVE-2008-5918 CVE-2008-5919
Created:March 9, 2009 Updated:March 11, 2009
Description:

From the Gentoo advisory:

James Bercegay of GulfTech Security reported a Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl() function in index.php (CVE-2008-5918) and a directory traversal vulnerability in rss.php when magic_quotes_gpc is disabled (CVE-2008-5919).

A remote attacker can exploit these vulnerabilities to overwrite arbitrary files, to read changelogs or diffs for restricted projects and to hijack a user's session.

Alerts:
Gentoo 200903-20 2009-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds