CVE-2011-0728
Loggerhead < 1.18.1 - Authenticated Cross-Site Scripting via Filename in Revision View
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.
References (12)
Core 12
Core References
Patch x_refsource_confirm
https://launchpad.net/loggerhead/1.18/1.18.1
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057502.html
Patch x_refsource_confirm
https://bugs.launchpad.net/loggerhead/+bug/740142
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0849
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/47032
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057413.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43822
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0848
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/71279
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057479.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/44017
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/66305
Scores
EPSS
0.0181
EPSS Percentile
76.4%
Details
CWE
CWE-79
Status
published
Products (6)
michael_hudson-doyle/loggerhead
1.6
michael_hudson-doyle/loggerhead
1.6.1
michael_hudson-doyle/loggerhead
1.10
michael_hudson-doyle/loggerhead
1.17
michael_hudson-doyle/loggerhead
< 1.18
pypi/loggerhead
0 - 1.18.1PyPI
Published
Mar 29, 2011
Tracked Since
Feb 18, 2026