FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-5650

This CVE name corresponds to:

Entered Topic
2013-05-26 couchdb -- DOM based Cross-Site Scripting via Futon UI

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-5650
Phase Assigned(20121024)

Description

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.

References

Source Reference
BUGTRAQ 20130114 CVE-2012-5650 Apache CouchDB DOM based Cross-Site Scripting via Futon UI
MLIST [couchdb-user] 20130114 CVE-2012-5650 Apache CouchDB DOM based Cross-Site Scripting via Futon UI