CVE-2004-1318

NameCVE-2004-1318
DescriptionCross-site scripting (XSS) vulnerability in namazu.cgi for Namazu 2.0.13 and earlier allows remote attackers to inject arbitrary HTML and web script via a query that starts with a tab ("%09") character, which prevents the rest of the query from being properly sanitized.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-627-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
namazu2 (PTS)wheezy2.0.21-6fixed
jessie2.0.21-10fixed
stretch2.0.21-20fixed
buster, sid2.0.21-21fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
namazu2source(unstable)2.0.14-1medium
namazu2sourcewoody2.0.10-1woody3mediumDSA-627-1

Search for package or bug name: Reporting problems