CVE-2014-3247

NameCVE-2014-3247
DescriptionCross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs748828

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
collabtivesource(unstable)2.0+dfsg-1748828

Notes

[wheezy] - collabtive <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems