exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 1 of 1 RSS Feed

Files

ViewVC Regular Expression Search Cross-Site Scripting
Posted Mar 31, 2010
Site secunia.com

Secunia Research has discovered a vulnerability in ViewVC, which can be exploited by malicious people to conduct cross-site scripting attacks. Input passed to the regular expression search functionality is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Successful exploitation requires that the regular expression search functionality is enabled (disabled by default).

tags | advisory, arbitrary, xss
advisories | CVE-2010-0132
SHA-256 | 5134f35b273cbc82406c71d36a286ab9ee387d8b95bd20cc48b361730aa73186
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close