CVE-2009-2947
CVE-2009-2947
Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.xapian.org/pipermail/xapian-discuss/2009-September/007115.htmlhttp://secunia.com/advisories/36674http://secunia.com/advisories/36693http://svn.xapian.org/%2Acheckout%2A/tags/1.0.16/xapian-applications/omega/NEWShttp://www.debian.org/security/2009/dsa-1882http://www.securityfocus.com/bid/36317