Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 135650 - net-www/dotproject <2.0.3 : XSS
Summary: net-www/dotproject <2.0.3 : XSS
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/20418/
Whiteboard: ~4 [noglsa] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-05 10:03 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2006-06-11 13:37 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-05 10:03:42 UTC
Software:	dotProject 2.x

Description:
A vulnerability has been reported in dotProject, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed to unspecified parameters isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Successful exploitation requires that the Internet Explorer browser is used.

The vulnerability has been reported in version 2.0.2 and prior.

Solution:
Update to version 2.0.3.
http://sourceforge.net/project/showfiles.php?group_id=21656

Provided and/or discovered by:
Secure Sky Technology

Original Advisory:
dotProject:
http://sourceforge.net/project/shownotes.php?release_id=422371

JVN:
http://jvn.jp/jp/JVN%2397636431/index.html
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-06-05 10:04:12 UTC
Hi Stuart, please bump 2.0.3 when you have time
Comment 2 Stuart Herbert (RETIRED) gentoo-dev 2006-06-11 10:01:41 UTC
Bumped; older versions removed.

Best regards,
Stu
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-11 13:37:54 UTC
Thx SuperStu. Closing without GLSA as this is rated ~.