User Friendly svn xss Vulnerability (CVE-2014-4719)
Release date:
Updated on:
Affected Systems:
USVN <1.0.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68155
CVE (CAN) ID: CVE-2014-4719
User-Friendly USVN is a Web interface written in PHP to configure the Subversion repository.
User-Friendly SVN (USVN) versions earlier than 1.0.7 have a cross-site scripting vulnerability in the logon panel. Remote attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML files through the username field.
<* Source: Manish Tanwar
Link: http://packetstormsecurity.com/files/127177/User-Friendly-SVN-Cross-Site-Scripting.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
USVN
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.usvn.info/
This article permanently updates the link address: