CVE-2005-4831 Information
Feb 14, 2021
cve
Description
viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter which can be leveraged for cross-site scripting (XSS) and other attacks as demonstrated using (1) \text/html\ or (2) \image/jpeg\ with an image that is rendered as HTML by Internet Explorer a different vulnerability than CVE-2004-1062. NOTE: it was later reported that 0.9.4 is also affected.
Reference
http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030514.html http://www.securityfocus.com/archive/1/461382/100/0/threaded http://www.securityfocus.com/bid/12112 http://www.securitytracker.com/id?1017704
Share on: