Gentoo: GLSA-200412-23: Zwiki: XSS vulnerability
Summary
Gentoo Linux Security Advisory GLSA 200412-23
https://security.gentoo.org/
Severity: Low
Title: Zwiki: XSS vulnerability
Date: December 21, 2004
Bugs: #72315
ID: 200412-23
Synopsis
=======
Zwiki is vulnerable to cross-site scripting attacks.
Background
=========
Zwiki is a Zope wiki-clone for easy-to-edit collaborative websites.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-zope/zwiki < 0.36.2-r1 >= 0.36.2-r1
==========
Due to improper input validation, Zwiki can be exploited to perform
cross-site scripting attacks.
Impact
=====
By enticing a user to read a specially-crafted wiki entry, an attacker
can execute arbitrary script code running in the ...
Resolution
References
Availability
Concerns
Background