Oval Definition:
oval:org.mitre.oval:def:20108
Revision Date
:
2014-06-23
Version
:
8
Title
:
DSA-2474-1 ikiwiki - cross-site scripting
Description
:
Raúl Benencia discovered that ikiwiki, a wiki compiler, does not properly escape the author (and its URL) of certain metadata, such as comments. This might be used to conduct cross-site scripting attacks.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2012-0220
DSA-2474-1
Platform(s)
:
Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s)
:
ikiwiki
Definition Synopsis
Debian 6.0 is installed
AND
GNU/Linux or GNU/kFreeBSD kernel
Debian GNU/Linux is installed
OR
Debian GNU/kFreeBSD is installed
AND
ikiwiki DPKG is earlier than 0:3.20100815.9
BACK