Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 258779 (CVE-2009-0417) - <dev-php5/agavi-0.11.6 AgaviWebRouting::gen(null) XSS (CVE-2009-0417)
Summary: <dev-php5/agavi-0.11.6 AgaviWebRouting::gen(null) XSS (CVE-2009-0417)
Status: RESOLVED FIXED
Alias: CVE-2009-0417
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-02-12 20:29 UTC by Robert Buchholz (RETIRED)
Modified: 2010-08-01 12:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-02-12 20:29:15 UTC
CVE-2009-0417 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0417):
  Cross-site scripting (XSS) vulnerability in the
  AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0
  before 1.0.0 beta 8 allows remote attackers to inject arbitrary web
  script or HTML via a crafted URL with certain characters that are not
  properly handled by web browsers that do not strictly follow RFC
  3986, such as Internet Explorer 6 and 7.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-03-04 16:44:33 UTC
ping
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2009-07-15 15:45:02 UTC
ping, php herd please bump
Comment 3 Jaak Ristioja 2010-07-23 08:58:53 UTC
There is no <dev-php5/agavi-1.0.3 in portage any more.
Comment 4 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 12:13:31 UTC
Got bumped, XSS -> Closing noglsa.