5 results (0.002 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting (XSS) and other attacks, as demonstrated using (1) "text/html", or (2) "image/jpeg" with an image that is rendered as HTML by Internet Explorer, a different vulnerability than CVE-2004-1062. NOTE: it was later reported that 0.9.4 is also affected. • http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030514.html http://www.securityfocus.com/archive/1/461382/100/0/threaded http://www.securityfocus.com/bid/12112 http://www.securitytracker.com/id?1017704 •

CVSS: 7.6EPSS: 0%CPEs: 1EXPL: 1

CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter. • http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030514.html http://www.securityfocus.com/archive/1/461382/100/0/threaded http://www.securityfocus.com/bid/12112 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/030222.html http://security.gentoo.org/glsa/glsa-200412-26.xml http://www.mikx.de/index.php?p=6 http://www.novell.com/linux/security/advisories/2005_01_sr.html https://exchange.xforce.ibmcloud.com/vulnerabilities/18718 •

CVSS: 5.0EPSS: 0%CPEs: 13EXPL: 0

Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information. Múltiples vulnerabilidades desconocidas en viewcvs anteriores a 0.9.2, cuando se exporta un repositorio como un archivo tar, no implementa apropiadamente las configuraciones hide_cvsroot y forbidden_settings, lo que podría permitir a atacantes remotos obtener información sensible. • http://www.debian.org/security/2004/dsa-605 https://exchange.xforce.ibmcloud.com/vulnerabilities/18369 •

CVSS: 6.4EPSS: 1%CPEs: 4EXPL: 2

Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters. • https://www.exploit-db.com/exploits/21473 http://archives.neohapsis.com/archives/bugtraq/2002-05/0161.html http://www.iss.net/security_center/static/9112.php http://www.securityfocus.com/bid/4818 •