LWN.net Logo

backuppc: cross-site scripting

Package(s):backuppc CVE #(s):CVE-2011-4923
Created:July 9, 2012 Updated:July 11, 2012
Description: From the Mageia advisory:

Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file viewer

Alerts:
Mageia MGASA-2012-0139 2012-07-09
Mageia MGASA-2012-0165 2012-07-14
Mandriva MDVSA-2013:062 2013-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds