Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 182054 - net-www/dotproject < 2.1-RC2 XSS (CVE-2007-3226)
Summary: net-www/dotproject < 2.1-RC2 XSS (CVE-2007-3226)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://secunia.com/advisories/25638/
Whiteboard: ~4 [noglsa] jaervosz
Keywords:
: 182675 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-06-14 19:49 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-08-09 12:13 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-14 19:49:38 UTC
Description:
A vulnerability has been reported in dotProject, which can be exploited by malicious people to conduct cross-site scripting attacks.
 
 Input passed to certain parameters is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
 
 The vulnerability is reported in versions 2.0.4 and prior.

Solution:
The vulnerability is fixed in version 2.1 RC2.
 http://sourceforge.net/project/showfiles.php?group_id=21656&package_id=30225

Provided and/or discovered by:
Fukumori

Original Advisory:
JVN:
 http://jvn.jp/jp/JVN%2363602912/index.html
 
 dotProject:
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-06-20 14:29:20 UTC
*** Bug 182675 has been marked as a duplicate of this bug. ***
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-07-14 22:39:06 UTC
web-apps, please advise and bump as necessary.
Comment 3 Gunnar Wrobel (RETIRED) gentoo-dev 2007-08-09 11:50:43 UTC
Bumped to 2.1_rc2 removed 2.0.4. Unstable on all archs, guess this can be marked as fixed.
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-09 12:13:02 UTC
"indeed" (c) Teal'c