![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2003-0154 |
Description: | Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2003-0154 BugTraq ID: 5516 http://www.securityfocus.com/bid/5516 Bugtraq: 20020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilities (Google Search) http://marc.info/?l=bugtraq&m=102980129101054&w=2 Debian Security Information: DSA-265 (Google Search) http://www.debian.org/security/2003/dsa-265 http://bugzilla.mozilla.org/show_bug.cgi?id=146244 XForce ISS Database: bonsai-error-message-xss(9920) http://www.iss.net/security_center/static/9920.php |