Release date: 2012-03-21
Updated on: 2012-03-23
Affected Systems:
Apache Group Wicket 1.4.18
Apache Group Wicket 1.4.17
Apache Group Wicket 1.4.16
Apache Group Wicket 1.4.15
Unaffected system:
Apache Group Wicket 1.4.20
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52680
Cve id: CVE-2012-0047
Wicket provides an object-oriented method for developing Web-based Dynamic UI applications.
Apache Wicket may have XSS attacks when operating the 'wicket: pagemapname' request parameter value. attackers can execute arbitrary script code.
<* Source: Jens Schenck
Link: http://wicket.apache.org/2012/03/22/wicket-cve-2012-0047.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/