Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2010-0736

Disclosure Date: March 19, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via "user-provided input."
0
Attacker Value
Unknown

CVE-2010-0005

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.
0
Attacker Value
Unknown

CVE-2010-0004

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.
0
Attacker Value
Unknown

CVE-2009-3619

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing illegal parameter names and values."
0
Attacker Value
Unknown

CVE-2009-3618

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the view parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-4325

Disclosure Date: September 30, 2008 (last updated October 04, 2023)
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.
0
Attacker Value
Unknown

CVE-2008-1291

Disclosure Date: March 24, 2008 (last updated October 04, 2023)
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.
0
Attacker Value
Unknown

CVE-2008-1290

Disclosure Date: March 24, 2008 (last updated October 04, 2023)
ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2008-1292

Disclosure Date: March 24, 2008 (last updated October 04, 2023)
ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.
0
Attacker Value
Unknown

CVE-2006-5442

Disclosure Date: October 21, 2006 (last updated October 04, 2023)
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view.
0