LWN.net Logo

backuppc: cross-site scripting

Package(s):backuppc CVE #(s):CVE-2011-3361
Created:October 28, 2011 Updated:February 2, 2012
Description: From the Ubuntu advisory:

It was discovered that BackupPC did not properly sanitize its input when processing backup browser error messages, resulting in a cross-site scripting (XSS) vulnerability. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain.

Alerts:
Ubuntu USN-1249-1 2011-10-27
Fedora FEDORA-2012-0826 2012-02-01
Fedora FEDORA-2012-0825 2012-02-01

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds