ViewVC 'lib/viewvc.py' Cross Site Scripting Vulnerability
BID:38650
Info
ViewVC 'lib/viewvc.py' Cross Site Scripting Vulnerability
| Bugtraq ID: | 38650 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2010-0736 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2010 12:00AM |
| Updated: | May 07 2015 05:18PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
ViewVC ViewVC 1.1.3 ViewVC ViewVC 1.1.2 ViewVC ViewVC 1.0.8 ViewVC ViewVC 1.0.5 ViewVC ViewVC 1.0.3 ViewVC ViewVC 1.0.2 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 |
| Not Vulnerable: |
ViewVC ViewVC 1.1.4 ViewVC ViewVC 1.0.10 |
Discussion
ViewVC 'lib/viewvc.py' Cross Site Scripting Vulnerability
ViewVC is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to ViewVC 1.1.4 and 1.0.10 are vulnerable.
ViewVC is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to ViewVC 1.1.4 and 1.0.10 are vulnerable.
Exploit / POC
ViewVC 'lib/viewvc.py' Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
ViewVC 'lib/viewvc.py' Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ViewVC 'lib/viewvc.py' Cross Site Scripting Vulnerability
References:
References:
- ViewVC Changelog (ViewVC)
- ViewVC Tigris Homepage (ViewVC)