CVE-2004-1318

NameCVE-2004-1318
DescriptionCross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-627-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
namazu2 (PTS)bookworm, bullseye2.0.21-23fixed
sid, trixie2.0.21-25fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
namazu2sourcewoody2.0.10-1woody3DSA-627-1
namazu2source(unstable)2.0.14-1

Search for package or bug name: Reporting problems