Zwiki: XSS vulnerability
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200412-23 / zwiki |
| Release Date |
December 21, 2004 |
| Latest Revision |
May 22, 2006: 02 |
| Impact |
low |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-zope/zwiki |
<
0.36.2-r1 |
>=
0.36.2-r1 |
All supported architectures
|
Related bugreports:
#72315
Synopsis
Zwiki is vulnerable to cross-site scripting attacks.
2.
Impact Information
Background
Zwiki is a Zope wiki-clone for easy-to-edit collaborative websites.
Description
Due to improper input validation, Zwiki can be exploited to perform
cross-site scripting attacks.
Impact
By enticing a user to read a specially-crafted wiki entry, an attacker
can execute arbitrary script code running in the context of the
victim's browser.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Zwiki users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-zope/zwiki-0.36.2-r1"
|
4.
References
|