Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1882-1 | New xapian-omega packages fix cross-site scripting |
EUVD |
EUVD-2009-2934 | Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T16:43:31.029Z
Reserved: 2009-08-23T00:00:00Z
Link: CVE-2009-2947
No data.
Status : Deferred
Published: 2009-09-14T16:30:00.500
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2947
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD