|
|
Log in / Subscribe / Register

xapian-omega: missing input sanitising

Package(s):xapian-omega CVE #(s):CVE-2009-2947
Created:September 10, 2009 Updated:September 16, 2009
Description: From the Debian alert:

It was discovered that xapian-omega, a CGI interface for searching xapian databases, is not properly escaping user supplied input when printing exceptions. An attacker can use this to conduct cross-site scripting attacks via crafted search queries resulting in an exception and steal potentially sensitive data from web applications running on the same domain or embedding the search engine into a website.

Alerts:
Debian DSA-1882-1 xapian-omega 2009-09-09

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds