LWN.net Logo

git: cross-site scripting

Package(s):git CVE #(s):CVE-2010-3906
Created:December 16, 2010 Updated:February 22, 2011
Description:

From the Mandriva advisory:

A cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and previous versions allows remote attackers to inject arbitrary web script or HTML code via f and fp variables (CVE-2010-3906).

Alerts:
SUSE SUSE-SR:2011:004 2011-02-22
openSUSE openSUSE-SU-2011:0115-1 2011-02-16
Fedora FEDORA-2010-18973 2010-12-17
Fedora FEDORA-2010-18981 2010-12-17
Red Hat RHSA-2010:1003-01 2010-12-21
Mandriva MDVSA-2010:256 2010-12-16
Oracle ELSA-2013-0589 2013-03-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds