xapian-omega: missing input sanitising
| Package(s): | xapian-omega |
CVE #(s): | CVE-2009-2947
|
| Created: | September 10, 2009 |
Updated: | September 16, 2009 |
| Description: |
From the Debian alert:
It was discovered that xapian-omega, a CGI interface for searching xapian
databases, is not properly escaping user supplied input when printing
exceptions. An attacker can use this to conduct cross-site scripting
attacks via crafted search queries resulting in an exception and steal
potentially sensitive data from web applications running on the same domain
or embedding the search engine into a website. |
| Alerts: |
|