CVE-2011-0728

Loggerhead < 1.18.1 - Authenticated Cross-Site Scripting via Filename in Revision View

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.

References (12)

Core 12
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057502.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0849
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47032
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057413.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43822
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0848
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/71279
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057479.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44017
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/66305

Scores

EPSS 0.0181
EPSS Percentile 76.4%

Details

CWE
CWE-79
Status published
Products (6)
michael_hudson-doyle/loggerhead 1.6
michael_hudson-doyle/loggerhead 1.6.1
michael_hudson-doyle/loggerhead 1.10
michael_hudson-doyle/loggerhead 1.17
michael_hudson-doyle/loggerhead < 1.18
pypi/loggerhead 0 - 1.18.1PyPI
Published Mar 29, 2011
Tracked Since Feb 18, 2026