Oval Definition:
oval:org.mitre.oval:def:7949
Revision Date
:
2014-06-23
Version
:
18
Title
:
DSA-1486 gnatsweb -- cross-site scripting
Description
:
r0t discovered that gnatsweb, a web interface to GNU GNATS, did not correctly sanitise the database parameter in the main CGI script. This could allow the injection of arbitrary HTML, or JavaScript code.
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2007-2808
DSA-1486
Platform(s)
:
Debian GNU/Linux 4.0
Product(s)
:
gnatsweb
Definition Synopsis
Debian GNU/Linux 4.0 is installed.
AND
Installed architecture is all
AND
gnatsweb is earlier than 4.00-1etch1
BACK