FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2947

This CVE name corresponds to:

Entered Topic
2009-09-13 xapian-omega -- cross-site scripting vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2947
Phase Assigned(20090823)

Description

Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.

References

Source Reference
MLIST [xapian-discuss] 20090909 Cross-site scripting issue in Omega
CONFIRM http://svn.xapian.org/*checkout*/tags/1.0.16/xapian-applications/omega/NEWS
DEBIAN DSA-1882
BID 36317
SECUNIA 36674
SECUNIA 36693