![]() |
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ....
|
Guardian Digital Inc. > InfoCenter > Mailing List Archives > BugTraq BugTraq Mailing List Archive
From: Luke Macken (lewk@gentoo.org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Low
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
Zwiki is vulnerable to cross-site scripting attacks.
Background
Zwiki is a Zope wiki-clone for easy-to-edit collaborative websites.
Affected packages
-------------------------------------------------------------------
Description
Due to improper input validation, Zwiki can be exploited to perform
Impact
By enticing a user to read a specially-crafted wiki entry, an attacker
Workaround
There is no known workaround at this time.
Resolution
All Zwiki users should upgrade to the latest version:
# emerge --sync
References
[ 1 ] Zwiki Bug Report
Availability
This GLSA and any updates to it are available for viewing at
http://security.gentoo.org/glsa/glsa-200412-23.xml
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the
License
Copyright 2004 Gentoo Foundation, Inc; referenced text
The contents of this document are licensed under the
http://creativecommons.org/licenses/by-sa/2.0
|