Koala Framework before 2011-11-21 has XSS via the request_uri parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.cloudscan.me/2011/12/cve-2011-5018-koala-framework-xss.html | third party advisory exploit |
https://groups.google.com/forum/#%21topic/koala-framework-dev/wgHDD7N7qhk | |
https://github.com/koala-framework/koala-framework/commit/59f81ea6bd8ef96c04a706a3ca453cd656284faa | third party advisory patch |