CVE-2009-4078 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Reference

http://jvn.jp/en/jp/JVN01245481/index.html http://jvn.jp/en/jp/JVN87341298/index.html http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000073.html http://rubyforge.org/frs/shownotes.php?release_id=41108 http://secunia.com/advisories/37420 http://www.redmine.org/wiki/redmine/Changelogv086-2009-11-04 http://www.securityfocus.com/bid/37066 http://www.vupen.com/english/advisories/2009/3291 https://exchange.xforce.ibmcloud.com/vulnerabilities/54333

Share on: