FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-1453

This CVE name corresponds to:

Entered Topic
2010-05-07 piwik -- cross site scripting vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-1453
Phase Assigned(20100415)

Description

Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

References

Source Reference
MLIST [oss-security] 20100505 CVE Request - Piwik 0.5.5 - XSS vulnerability
MLIST [oss-security] 20100505 Re: CVE Request - Piwik 0.5.5 - XSS vulnerability
CONFIRM http://piwik.org/blog/2010/04/piwik-0-6-security-advisory/
SECUNIA 39666
VUPEN ADV-2010-1079