LWN.net Logo

conga: cross-site scripting

Package(s):conga CVE #(s):CVE-2010-1104 CVE-2011-1948
Created:February 21, 2012 Updated:March 8, 2012
Description: From the Red Hat advisory:

Multiple cross-site scripting (XSS) flaws were found in luci, the conga web-based administration application. If a remote attacker could trick a user, who was logged into the luci interface, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's luci session. (CVE-2010-1104, CVE-2011-1948)

Alerts:
Red Hat RHSA-2012:0151-03 2012-02-21
Scientific Linux SL-cong-20120306 2012-03-06
Oracle ELSA-2012-0151 2012-03-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds