LWN.net Logo

perl-HTML-Template-Pro: cross-site scripting

Package(s):perl-HTML-Template-Pro CVE #(s):CVE-2011-4616
Created:October 15, 2012 Updated:October 22, 2012
Description: From the CVE entry:

Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.

Alerts:
Fedora FEDORA-2012-15490 2012-10-14
Fedora FEDORA-2012-15482 2012-10-14
Mageia MGASA-2012-0302 2012-10-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds