CVE-2009-0359

Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nongnu:samizdat:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:59

Type Values Removed Values Added
References () http://osvdb.org/52022 - () http://osvdb.org/52022 -
References () http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch - Vendor Advisory () http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch - Vendor Advisory
References () http://www.mail-archive.com/debian-testing-security-announce%40lists.debian.org/msg00171.html - () http://www.mail-archive.com/debian-testing-security-announce%40lists.debian.org/msg00171.html -
References () http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html - Patch, Vendor Advisory () http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/500961/100/0/threaded - () http://www.securityfocus.com/archive/1/500961/100/0/threaded -
References () http://www.securityfocus.com/bid/33768 - Patch () http://www.securityfocus.com/bid/33768 - Patch

07 Nov 2023, 02:03

Type Values Removed Values Added
References
  • {'url': 'http://www.mail-archive.com/debian-testing-security-announce@lists.debian.org/msg00171.html', 'name': '[debian-testing-security-announce] 20090211 Security update for Debian Testing - 2009-02-12', 'tags': [], 'refsource': 'MLIST'}
  • () http://www.mail-archive.com/debian-testing-security-announce%40lists.debian.org/msg00171.html -

Information

Published : 2009-02-17 17:30

Updated : 2024-11-21 00:59


NVD link : CVE-2009-0359

Mitre link : CVE-2009-0359

CVE.ORG link : CVE-2009-0359


JSON object : View

Products Affected

nongnu

  • samizdat
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')