gnatsweb: cross-site scripting
| Package(s): | gnatsweb | CVE #(s): | CVE-2007-2808 | ||||
| Created: | February 6, 2008 | Updated: | February 6, 2008 | ||||
| Description: | From the Debian advisory: "r0t" discovered that gnatsweb, a web interface to GNU GNATS, did not correctly sanitize the database parameter in the main CGI script. This could allow the injection of arbitrary HTML, or javascript code. | ||||||
| Alerts: |
| ||||||
