php-zendframework: cross-site scripting
| Package(s): | php-ZendFramework | CVE #(s): | |||||||||
| Created: | March 14, 2011 | Updated: | March 16, 2011 | ||||||||
| Description: | From the Zend Framework advisory:
The default error handling view script generated using Zend_Tool failed to escape request parameters when run in the "development" configuration environment, providing a potential XSS attack vector. | ||||||||||
| Alerts: |
| ||||||||||
