View Single Post
Old 2006-01-25, 11:41 AM   #1
ScannerX
Banned
 
Join Date: Jan 2006
Posts: 8
New Apache Cross site scripting vulnerability

Input passed in the URL isn't properly sanitized before being used by the Web-Access-Log viewer. This can be exploited to execute arbitrary JavaScript code in user's browser session in context of an affected website when a malicious log entry is viewed in Geronimo-admin.
http://issues.apache.org/jira/browse/GERONIMO-1474
ScannerX is offline   Reply With Quote