CVE-2004-1318

Cross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:namazu:namazu:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:namazu:namazu:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:namazu:namazu:2.0.13:*:*:*:*:*:*:*

History

20 Nov 2024, 23:50

Type Values Removed Values Added
References () http://jvn.jp/jp/JVN%23904429FE.html - Vendor Advisory () http://jvn.jp/jp/JVN%23904429FE.html - Vendor Advisory
References () http://secunia.com/advisories/13600 - () http://secunia.com/advisories/13600 -
References () http://securitytracker.com/alerts/2005/Jan/1012802.html - () http://securitytracker.com/alerts/2005/Jan/1012802.html -
References () http://securitytracker.com/alerts/2005/Jan/1012805.html - () http://securitytracker.com/alerts/2005/Jan/1012805.html -
References () http://www.debian.org/security/2005/dsa-627 - Vendor Advisory () http://www.debian.org/security/2005/dsa-627 - Vendor Advisory
References () http://www.linuxsecurity.com/content/view/117604/102/ - () http://www.linuxsecurity.com/content/view/117604/102/ -
References () http://www.namazu.org/security.html.en#xss-tab - Patch, Vendor Advisory () http://www.namazu.org/security.html.en#xss-tab - Patch, Vendor Advisory
References () http://www.novell.com/linux/security/advisories/2005_01_sr.html - () http://www.novell.com/linux/security/advisories/2005_01_sr.html -
References () http://www.osvdb.org/12516 - () http://www.osvdb.org/12516 -
References () http://www.securityfocus.com/advisories/9028 - () http://www.securityfocus.com/advisories/9028 -
References () http://www.securityfocus.com/bid/12053 - () http://www.securityfocus.com/bid/12053 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18623 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18623 -

Information

Published : 2005-01-06 05:00

Updated : 2024-11-20 23:50


NVD link : CVE-2004-1318

Mitre link : CVE-2004-1318

CVE.ORG link : CVE-2004-1318


JSON object : View

Products Affected

namazu

  • namazu