SuSE: 2013:0053-1: important: WebYaST
Summary
The hosts list used by WebYaST for connecting to it's back
end part was modifiable allowing to point to a malicious
website which then could access all values sent by WebYaST.
The /host configuration path was removed to fix this issue.
Security Issue reference:
* CVE-2012-0435
References
#792712
Cross- CVE-2012-0435
Affected Products:
WebYaST 1.2
SUSE Studio Standard Edition 1.2
https://www.suse.com/security/cve/CVE-2012-0435.html
https://bugzilla.novell.com/792712
https://login.microfocus.com/nidp/app/login