Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.
Link | Tags |
---|---|
http://www.openca.org/news/CAN-2004-0787.txt | patch vendor advisory |
http://marc.info/?l=bugtraq&m=109448767123954&w=2 | mailing list |
http://www.securityfocus.com/bid/11113 | vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17274 | vdb entry |