LWN.net Logo

ReviewBoard: cross-site scripting

Package(s):ReviewBoard CVE #(s):CVE-2011-4312
Created:November 29, 2011 Updated:November 30, 2011
Description: From the Red Hat bugzilla:

A cross-site scripting (XSS) flaw was found in the way the commenting system of the ReviewBoard, a web-based code review tool, sanitized user input (new comments to be loaded). A remote attacker could provide a specially-crafted URL, which once visited by valid ReviewBoard user could lead to arbitrary HTML or web script execution in the 'diff viewer' or 'screenshot pages' components.

Alerts:
Fedora FEDORA-2011-15933 2011-11-15
Fedora FEDORA-2011-15935 2011-11-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds