CVE-2010-1625

NameCVE-2010-1625
DescriptionCross-site scripting (XSS) vulnerability in LXR Cross Referencer before 0.9.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the search body and the results page for a search, a different vulnerability than CVE-2009-4497 and CVE-2010-1448.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2092-1
NVD severitymedium (attack range: remote)
Debian Bugs588137, 588138

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lxrsource(unstable)(unfixed)low588138
lxr-cvssource(unstable)0.9.5+cvs20071020-1.1low588137
lxr-cvssourcelenny0.9.5+cvs20071020-1+lenny1mediumDSA-2092-1

Notes

[lenny] - lxr <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems