Bug 399561 (CVE-2007-6110) - CVE-2007-6110 htdig htsearch XSS vulnerability
Summary: CVE-2007-6110 htdig htsearch XSS vulnerability
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-6110
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard:
Depends On: 401111 401121 401131 401141
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-11-26 15:40 UTC by Tomas Hoger
Modified: 2019-09-29 12:22 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-12-20 11:43:56 UTC
Embargoed:


Attachments (Terms of Use)
Patch from Michael Skibbe (reporter of the issue) (1.10 KB, patch)
2007-11-28 09:03 UTC, Tomas Hoger
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:1095 0 normal SHIPPED_LIVE Moderate: htdig security update 2007-12-03 15:48:35 UTC

Description Tomas Hoger 2007-11-26 15:40:19 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6110 to the following vulnerability:

Cross-site scripting (XSS) vulnerability in htsearch in htdig 3.2.0b6
allows remote attackers to inject arbitrary web script or HTML via the
sort parameter.

References:
http://sourceforge.net/mailarchive/forum.php?thread_name=200709251310.55835.mskibbe%40suse.de&forum_name=htdig-dev

Comment 5 Tomas Hoger 2007-11-28 09:03:35 UTC
Created attachment 271081 [details]
Patch from Michael Skibbe (reporter of the issue)

Replaces error message:

  No such sort method: `<user supplied input here>'

with simple:

  invalid sort method

Comment 6 Adam Tkac 2007-11-28 09:53:55 UTC
Patch looks fine


Note You need to log in before you can comment on or make changes to this bug.