LWN.net Logo

ejabberd: cross-site scripting vulnerability

Package(s):ejabberd CVE #(s):CVE-2009-0934
Created:March 19, 2009 Updated:April 17, 2009
Description: ejabberd has a cross-site scripting vulnerability. From the Fedora alert:

Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.

Alerts:
Debian DSA-1774-1 2009-04-17
Fedora FEDORA-2009-2746 2009-03-16
Fedora FEDORA-2009-2747 2009-03-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds