383
VMScore

CVE-2016-2511

Published: 07/04/2016 Updated: 03/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the path parameter to log.php.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 7.0

websvn websvn

Vendor Advisories

Jakub Palaczynski discovered that websvn, a web viewer for Subversion repositories, does not correctly sanitize user-supplied input, which allows a remote user to run reflected cross-site scripting attacks For the oldstable distribution (wheezy), this problem has been fixed in version 233-11+deb7u2 For the stable distribution (jessie), this pr ...

Exploits

WebSVN version 233 suffers from a cross site scripting vulnerability ...
Opsview Monitor versions 52, 53, and 54 suffer from cross site scripting and multiple remote command execution vulnerabilities ...