Vulnerability title: Apache Wicket Cross-Site Scripting
Moderate hazard level
Whether or not to publish for the first time
Release date: 1.01.08.25
Vulnerability cause input verification error
Vulnerability-caused threats unauthorized information leakage
Affected Product Version
Apache Software Foundation
Apache Wicket 1.4.16
Apache Software Foundation
Apache Wicket 1.4.17
Vulnerability description Apache Wicket is a powerful, component-based lightweight Web application framework. Apache Wicket has the input verification vulnerability, which allows malicious attackers to perform cross-site scripting attacks. Some input passed to multi-window Support lacks filtering before returning users. Attackers can exploit this vulnerability to perform cross-site scripting attacks, construct malicious connections, and trick users into parsing, attackers can execute malicious script code on the target user's browser.
Cve id: CVE-2011-2712
Link:
Http://wicket.apache.org/2011/08/23/cve-2011-2712.html http://secunia.com/advisories/45727/
No verification information
Vulnerability solutions Apache Wicket 1.5-RC5.1 and 1.4.18 have fixed this vulnerability and we recommend that you download it using: http://wicket.apache.org/