loggerhead: cross-site scripting
| Package(s): | loggerhead | CVE #(s): | CVE-2011-0728 | ||||||||
| Created: | April 4, 2011 | Updated: | April 6, 2011 | ||||||||
| Description: | From the CVE entry:
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view. | ||||||||||
| Alerts: |
| ||||||||||
