|
|
| |
|
| |
loggerhead: cross-site scripting
| Package(s): | loggerhead |
CVE #(s): | CVE-2011-0728
|
| Created: | April 4, 2011 |
Updated: | April 6, 2011 |
| Description: |
From the CVE entry:
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view. |
| Alerts: |
|
( Log in to post comments)
|
|
|